CVE-2026-1929

HIGH

Advanced Woo Labels < 2.37 - Authenticated Remote Code Execution via get_select_option_values Callback Parameter

Title source: llm
STIX 2.1

Description

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the use of `call_user_func_array()` with user-controlled callback and parameters in the `get_select_option_values()` AJAX handler without an allowlist of permitted callbacks or a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP functions and operating system commands on the server via the 'callback' parameter.

Scores

CVSS v3 8.8
EPSS 0.0055
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
mihail-barinov/Advanced Woo Labels – Product Labels & Badges for WooCommerce < 2.36
Published Feb 25, 2026
Tracked Since Feb 25, 2026