PT-2026-21888 · WordPress · Advanced Woo Labels

Os

+1

·

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2026-1929

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Woo Labels versions prior to 2.3
Description The Advanced Woo Labels plugin for WordPress is susceptible to Remote Code Execution due to the use of call user func array() with user-controlled callback and parameters in the get select option values() AJAX handler. The lack of an allowlist of permitted callbacks or a capability check allows authenticated attackers with Contributor-level access or higher to execute arbitrary PHP functions and potentially operating system commands on the server via the callback parameter.
Recommendations Update Advanced Woo Labels to a version later than 2.3.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1929

Affected Products

Advanced Woo Labels