rootpwn

critical · CVSS v3 9.8 · EPSS 0.00184

CVE-2026-86591

The Botiga Pro WordPress plugin prior to version 1.6.5 contains a critical vulnerability in its REST API implementation due to a lack of aut

Overview

The Botiga Pro WordPress plugin prior to version 1.6.5 contains a critical vulnerability in its REST API implementation due to a lack of authorization checks. This flaw allows unauthenticated remote attackers to modify arbitrary site settings, potentially leading to full administrative takeover.

Description

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.

Impact

This vulnerability compromises Confidentiality, Integrity, and Availability by allowing unauthorized configuration changes and script injection. Site administrators and visitors are impacted as attackers can escalate privileges to gain full control or execute cross-site scripting (XSS) attacks across the entire front end. Additionally, the ability to trash posts directly impacts site content availability.

Remediation

Update the Botiga Pro plugin to version 1.6.5 or later immediately to apply the necessary authorization checks. If an immediate update is not possible, consider disabling the plugin or restricting access to the WordPress REST API via a web application firewall (WAF).

Risk context

With a CVSS score of 9.8, this is a critical-severity vulnerability that requires immediate attention. While the EPSS score of 0.00184 suggests low current exploitation activity, the ease of unauthenticated remote access makes it a high-priority target for automated attacks.

Affected products

  • Botiga Pro (WordPress plugin)

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
EPSS
0.00184

WordPress Plugin Broken Access Control Privilege Escalation XSS REST API Critical

← All CVEs