medium · CVSS v3 5.3 · EPSS 0.00186
CVE-2026-86785
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its RES…
Description
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00186