Description
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
Published: 2026-09-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated disclosure of WooCommerce API consumer key and secret
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in MgoSync WordPress plugin versions before 2.1.7. A REST API endpoint lacks authorization checks, enabling any user to retrieve the stored WooCommerce API consumer key and secret associated with the site. The exposed credentials provide read/write access to the WooCommerce API, allowing the attacker to perform any action that the API permits.

Affected Systems

Any WordPress site that has the MgoSync plugin installed with a version earlier than 2.1.7 is affected. The "/mgosync/api/credentials" endpoint is the specific target. The presence of WooCommerce is required because the credentials are tied to that plugin, but the vulnerability does not depend on theme or other plugins.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while an EPSS score of <1% suggests a low likelihood of exploitation noted at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint is reachable without authentication, exploitation requires only a simple HTTP request. Once an attacker obtains the consumer key and secret, the credentials grant full read/write permission to the store’s WooCommerce API, impacting confidentiality and integrity of store data.

Generated by OpenCVE AI on September 20, 2026 at 01:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MgoSync to version 2.1.7 or later, which removes the unauthenticated endpoint.
  • If an upgrade is not immediately possible, block or disable the affected REST endpoint using a firewall rule or .htaccess restriction to prevent unauthenticated access.
  • Monitor site logs for attempts to access the /mgosync/api/credentials endpoint and review WooCommerce API activity for anomalous use.

Generated by OpenCVE AI on September 20, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions mgosync
Vendors & Products Wordpress-extensions
Wordpress-extensions mgosync

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Sat, 19 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
Title MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure
References

Subscriptions

Wordpress-extensions Mgosync
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:17:41.413Z

Reserved: 2026-09-16T08:52:59.093Z

Link: CVE-2026-92404

cve-icon Vulnrichment

Updated: 2026-09-19T13:10:54.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:33.790

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:21Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor