Description
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation.

This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
Published: 2026-06-11
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Hippoo Mobile App for WooCommerce plugin contains an Incorrect Privilege Assignment flaw (CWE‑266) that permits an attacker to elevate their privileges within a WordPress site. By exploiting the plugin’s privilege assignment logic, a user with access to the plugin’s functionality can gain higher-level rights, potentially including administrator privileges. This can compromise the confidentiality, integrity, and availability of the entire WordPress installation, as privileged users may modify or delete content, change site settings, install additional malware, or access sensitive data.

Affected Systems

Affected installations of the Hippoo Mobile App for WooCommerce plugin up to and including version 1.9.4 are vulnerable. The flaw persists across all earlier releases, as no versioning information beyond the upper bound is provided. Site owners running the plugin in any WordPress environment should check their plugin version and upgrade if necessary.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity. The EPSS score is currently not available, yet the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector—based on the plugin nature—is that an authenticated user or a visitor who can interact with the plugin’s interface could trigger the flaw. Due to the high severity and the ease of privilege escalation, the risk to affected sites is substantial, and the vulnerability is considered exploitable by threat actors with moderate technical skill.

Generated by OpenCVE AI on June 11, 2026 at 22:30 UTC.

Remediation

Vendor Solution

Update the WordPress Hippoo Mobile App for WooCommerce Plugin to the latest available version (at least 1.9.5).


OpenCVE Recommended Actions

  • Update the Hippoo Mobile App for WooCommerce Plugin to version 1.9.5 or later.
  • Review and reduce WordPress user role assignments to eliminate over‑privileged accounts.
  • Restrict access to the plugin’s administrative interface to roles that truly require it, applying the principle of least privilege.
  • Regularly audit all plugins for similar privilege assignment issues and keep them updated.

Generated by OpenCVE AI on June 11, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hippooo
Hippooo hippoo Mobile App For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Hippooo
Hippooo hippoo Mobile App For Woocommerce
Wordpress
Wordpress wordpress

Thu, 11 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
Title WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hippooo Hippoo Mobile App For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-11T21:02:46.094Z

Reserved: 2026-05-27T10:26:36.700Z

Link: CVE-2026-49060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-11T22:16:57.737

Modified: 2026-06-11T22:16:57.737

Link: CVE-2026-49060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T22:45:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment