CVE-2026-16620 is an unauthenticated price manipulation vulnerability in the WPC Name Your Price for WooCommerce WordPress plugin in all versions before 2.2.5. The plugin fails to enforce server-side price validation for products in "Select" price mode, letting attackers complete orders at arbitrary prices below merchant-defined limits. It carries a HIGH severity CVSS v3.1 base score of 7.5.
