Wordpress Alert: Unauthorized price changes
A product endpoint accepts edits from a user without catalog rights. Products may be sold at unintended prices.
What it looks like
A product endpoint accepts edits from a user without catalog rights.
Why it matters
Products may be sold at unintended prices.
What to check
Audit product update permissions and recent price history.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce REST API overview, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #WooCommerce