Description
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Loss
Action: Immediate Patch
AI Analysis

Impact

The SKU Error Fixer for WooCommerce plugin prior to version 1.0 contains missing capability and nonce checks on two AJAX actions that can be invoked by anyone without authentication. These actions allow a remote attacker to permanently delete product variations that the plugin marks as obsolete and to retrieve detailed information about those variations, resulting in data loss and potential disclosure of product data. The vulnerability is a direct result of improper access control and a lack of protection mechanisms.

Affected Systems

All installations of the plugin identified as SKU Error Fixer for WooCommerce with a version of 1.0 or earlier are affected. Since the plugin is an unknown vendor product, any WordPress site that has installed this plugin in the specified versions is at risk. No product version information beyond 1.0 was provided, so any version equal to or older than 1.0 remains vulnerable.

Risk and Exploitability

The vulnerability is exploitable through unauthenticated HTTP requests to the plugin’s AJAX endpoints. No friction or discovery barrier is mentioned, suggesting that the attack can be performed by anyone able to send requests to the site. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the impact on data integrity and confidentiality implies a moderate to high severity. Without an available patch, the risk remains present until the plugin is updated or the endpoint is protected.

Generated by OpenCVE AI on October 9, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the SKU Error Fixer for WooCommerce plugin to the latest version (or remove it entirely if an upgrade is not available).
  • Restrict access to the two vulnerable AJAX endpoints by adding authentication checks, disabling them for unauthenticated users, or blocking them at the web‑server level.
  • Periodically back up product data and review orphaned product variations to ensure any accidental or malicious deletion can be reversed.

Generated by OpenCVE AI on October 9, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-352

Fri, 09 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
Title SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-09T06:00:07.694Z

Reserved: 2026-09-08T14:57:54.988Z

Link: CVE-2026-86850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T07:17:18.750

Modified: 2026-10-09T07:17:18.750

Link: CVE-2026-86850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:18Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)