Description
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration and synchronization changes
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization check on the plugin's REST API endpoints, allowing any visitor to modify Social Commerce for WooCommerce configuration settings and mark products as synchronized or not. This can alter how products appear on the front‑end, disable protective features, or trigger fraudulent sales actions. The weakness is a classic example of missing authorization control, as identified by CWE‑862.

Affected Systems

Social Commerce for WooCommerce, versions 2.5.4 and earlier, deployed on WordPress sites are impacted. No other vendors or product variants are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk; the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is purely web‑based: an unauthenticated user can access the vulnerable REST endpoints over HTTP or HTTPS by knowing or guessing the URL. No additional privileges or network access are required to exploit this flaw.

Generated by OpenCVE AI on September 23, 2026 at 13:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Social Commerce for WooCommerce to version 2.5.5 or later.
  • Configure the plugin’s REST API to require authentication, such as via OAuth or basic authentication.
  • If an upgrade is not possible, block or filter the vulnerable endpoints through a firewall or web application firewall to prevent unauthenticated access.

Generated by OpenCVE AI on September 23, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
Title Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T11:02:03.589Z

Reserved: 2026-09-08T11:49:45.537Z

Link: CVE-2026-86785

cve-icon Vulnrichment

Updated: 2026-09-23T10:40:11.631Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:04.233

Modified: 2026-09-23T12:17:08.477

Link: CVE-2026-86785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:45:04Z

Weaknesses