CVE-2025-12115
Last modified
CVE-2025-12115 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12115?
How severe is CVE-2025-12115?
How do I fix CVE-2025-12115?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12109The Header Footer Script Adder – Insert Code in Header, Body…6.4
- CVE-2025-1211Versions of the package hackney before 1.21.0 are vulnerable…6.5
- CVE-2025-12110A flaw was found in Keycloak. An offline session continues t…5.4
- CVE-2025-12112The Insert Headers and Footers Code – HT Script plugin for W…6.4
- CVE-2025-12113The Alt Text Generator AI – Auto Generate & Bulk Update Alt …4.3
- CVE-2025-12114Enabled serial console could potentially leak information th…5.5
- CVE-2025-12116The Drift theme for WordPress is vulnerable to Stored Cross-…6.4
- CVE-2025-12117The Renden theme for WordPress is vulnerable to Stored Cross…6.4
- CVE-2025-12118The Schema Scalpel plugin for WordPress is vulnerable to Sto…6.4
- CVE-2025-12119A mongoc_bulk_operation_t may read invalid memory if large o…3.3
- CVE-2025-1212An information disclosure vulnerability in GitLab CE/EE affe…7.5
- CVE-2025-12120Lite XL versions 2.1.8 and prior automatically execute the .…7.3
Are you affected by CVE-2025-12115?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
