Description
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated users can view or download sensitive information stored by the WordPress Ebook Store plugin in versions up to 6.19. The flaw lies in missing authorization checks when accessing protected data, allowing attackers to read private content without credentials. This results in a compromise of confidentiality that can affect users and store owners alike. This is a CWE‑862 Missing Authorization weakness.

Affected Systems

WordPress sites running the Ebook Store plugin from motov.net, versions 6.19 or earlier, are affected. Any installation that has not been updated to at least version 6.20 will remain vulnerable.

Risk and Exploitability

The CVSS score of 7.5 classifies this issue as High severity. Because authentication is not required, the attack vector is easily reachable from the outside; exploitation does not require special conditions or elevated privileges. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability, and the flaw is not cataloged in CISA KEV, but the lack of authentication combined with a high base score indicates that the risk of exploitation remains significant until the plug‑in is upgraded. This is a CWE‑862 Missing Authorization issue.

Generated by OpenCVE AI on August 4, 2026 at 14:00 UTC.

Remediation

Vendor Solution

Update the WordPress Ebook Store Plugin to the latest available version (at least 6.20).


OpenCVE Recommended Actions

  • Update the WordPress Ebook Store plugin to version 6.20 or later, which resolves the CWE‑862 Missing Authorization flaw.
  • If an immediate update is not possible, disable or remove the Ebook Store plugin until a patched version is available.
  • After remediation, verify that all protected data endpoints require proper authentication before access, ensuring the Missing Authorization issue is fully mitigated.

Generated by OpenCVE AI on August 4, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Motovnet
Motovnet ebook Store
Wordpress
Wordpress wordpress
Vendors & Products Motovnet
Motovnet ebook Store
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Title WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Motovnet Ebook Store
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:54:15.014Z

Reserved: 2026-07-05T21:27:42.077Z

Link: CVE-2026-59529

cve-icon Vulnrichment

Updated: 2026-07-27T14:54:09.316Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:03.310

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses