CVE-2026-88929: Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure
Published Sep 23, 2026
·Updated
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
Affected Software
1 affected component
Product Badge, Label, Countdown Timer for WooCommerce<7.5.2
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which products can be exposed to unauthenticated visitors?
Draft, pending, and private WooCommerce products may be exposed. An unauthenticated user can read their title, description, and price.
2
What versions are affected, and what version fixes the issue?
Versions 7.0.0 through 7.5.1 are affected. The issue is fixed in version 7.5.2; versions before 7.5.2 are vulnerable.
3
Does exploitation require an account or special permissions?
No. The vulnerable behavior returns product details to unauthenticated users, so an attacker does not need to log in.