Description
The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized post meta modification via AJAX
Action: Patch
AI Analysis

Impact

The Ibtana – Ecommerce Product Addons plugin contains a missing authorization check on the 'iepa_use_gt_editor' AJAX endpoint, allowing an attacker to modify or delete arbitrary post meta entries by manipulating the 'iepa_builder' key. This flaw can change plugin settings, pricing data, or other sensitive configurations, thereby compromising data integrity and potentially enabling further exploitation. The vulnerability is identified as a missing authorization weakness (CWE‑862).

Affected Systems

WordPress installations that have the vowelweb Ibtana – Ecommerce Product Addons plugin at any version up to and including 0.4.7.7 are affected. All earlier releases share the same vulnerability because the authorization check is absent in the code base used by these versions.

Risk and Exploitability

With a CVSS score of 5.3, the flaw ranks as medium severity. The EPSS score is less than 1% and the issue is not listed in CISA KEV, indicating that widespread exploitation is unlikely at present. However, exploitation requires an authenticated WordPress account with at least Subscriber-level privileges, so an attacker who compromises a legitimate user account or acquires credentials can trigger the attack. Due to the reasonable attack vector and the impact on configuration data, system administrators should consider the risk moderate and treat the vulnerability as a potential entry point for broader compromise if the compromised account has higher privileges.

Generated by OpenCVE AI on September 19, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Ibtana – Ecommerce Product Addons plugin to a version newer than 0.4.7.7, which incorporates the missing capability check.
  • If an immediate upgrade is not feasible, restrict access to the 'iepa_use_gt_editor' AJAX action by disabling the plugin or applying a file‑based access control rule that permits the endpoint only for administrator roles.
  • Monitor post meta tables and audit logs for unexpected changes, especially entries associated with the 'iepa_builder' key, to detect any unauthorized activity early.

Generated by OpenCVE AI on September 19, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Vowelweb
Vowelweb ibtana – Ecommerce Product Addons
Wordpress
Wordpress wordpress
Vendors & Products Vowelweb
Vowelweb ibtana – Ecommerce Product Addons
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.
Title Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Vowelweb Ibtana – Ecommerce Product Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:20.591Z

Reserved: 2026-02-05T14:54:33.493Z

Link: CVE-2026-1984

cve-icon Vulnrichment

Updated: 2026-09-19T13:50:40.935Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:53.467

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-1984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:19Z

Weaknesses