CVE-2026-62136: WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.
Affected Software
1 affected component
WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce<=2.3.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 2.3.22
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
Which plugin versions are affected?
Versions 2.3.21 and earlier are identified as affected.
3
What is the security impact?
The reported CVSS vector indicates network-reachable exploitation with no required privileges or user interaction, and an integrity impact rated low. No confidentiality or availability impact is specified.