CVE-2026-88929: Unknown Product Badge, Label, Countdown Timer For Woocommerce
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
Affected products
- Unknown Product Badge, Label, Countdown Timer For Woocommerce: from 7.0.0, before 7.5.2 (fixed in 7.5.2)
Published 2026-09-23. Last modified 2026-09-23.