Description
Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.
Published: 2026-01-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access / Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Missing authorization in the Hyyan WooCommerce Polylang Integration plugin allows users with insufficient privileges to perform actions reserved for higher-level accounts. Affected functions may include modifying product listings or language settings, potentially enabling unauthorized changes to store content. The weakness is identified as CWE‑862 and is rated with a CVSS score of 6.5, indicating moderate to high severity.

Affected Systems

The vulnerability affects all installations of the Hyyan WooCommerce Polylang Integration plugin version 1.5.0 or earlier on WordPress sites. The plugin is developed by Hyyan Abo Fakher and integrates WooCommerce with Polylang for multilingual e‑commerce sites. No version information beyond 1.5.0 is provided, so any deployment of the plugin that has not been upgraded should be considered at risk.

Risk and Exploitability

The risk level is moderate as reflected by the CVSS score, while the EPSS score of less than 1 % shows a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. An attacker could likely exploit this issue via web requests to plugin endpoints, given that standard WordPress authentication mechanisms do not enforce sufficient access controls when the plugin processes requests.

Generated by OpenCVE AI on April 16, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hyyan WooCommerce Polylang Integration to the latest release (currently above version 1.5.0).
  • Restrict administrative access to the plugin by limiting the WordPress roles that can manage WooCommerce and Polylang settings.
  • If an upgrade is not immediately possible, temporarily disable the plugin or block its URLs until a patched version is available.

Generated by OpenCVE AI on April 16, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Hyyan Abo Fakher
Hyyan Abo Fakher hyyan Woocommerce Polylang Integration
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Hyyan Abo Fakher
Hyyan Abo Fakher hyyan Woocommerce Polylang Integration
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Fri, 23 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.
Title WordPress Hyyan WooCommerce Polylang Integration plugin <= 1.5.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Hyyan Abo Fakher Hyyan Woocommerce Polylang Integration
Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:49.765Z

Reserved: 2026-01-23T12:32:07.880Z

Link: CVE-2026-24585

cve-icon Vulnrichment

Updated: 2026-01-23T21:21:40.572Z

cve-icon NVD

Status : Deferred

Published: 2026-01-23T15:16:16.513

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-24585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T01:45:20Z

Weaknesses