rootpwn

medium · CVSS v3 4.3 · EPSS 0.00232

CVE-2026-9766

The Empik for WooCommerce plugin for WordPress up to version 1.5.1 contains an authorization bypass vulnerability. This flaw arises from ins

Overview

The Empik for WooCommerce plugin for WordPress up to version 1.5.1 contains an authorization bypass vulnerability. This flaw arises from insufficient permission checks, allowing authenticated users with low privileges to alter product metadata. Consequently, store integrity and product management controls can be disrupted by unauthorized actors.

Description

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.

Impact

This vulnerability impacts the integrity of WooCommerce store data by allowing unauthorized modification of specific product metadata, such as logistics and export flags. The confidentiality and availability of the store remain unaffected. Attackers require authenticated subscriber-level access or higher to exploit this authorization flaw.

Remediation

Update the Empik for WooCommerce plugin to a version patched against this authorization bypass issue as soon as a fix is released by the vendor. Review WooCommerce product metadata logs for unexpected or unauthorized modifications. Enforce the principle of least privilege by strictly monitoring and auditing low-privileged user accounts, such as subscribers.

Risk context

This vulnerability is rated as medium severity with a CVSS v3 score of 4.3, indicating a moderate risk to application integrity. The current EPSS score of 0.00232 reflects a very low observed probability of exploitation in the wild, suggesting a measured, factual response is appropriate.

Affected products

  • Empik for WooCommerce plugin

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
EPSS
0.00232

wordpress woocommerce authorization-bypass plugin-vulnerability metadata-manipulation

← All CVEs