Description
The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized product metadata modification
Action: Update Plugin
AI Analysis

Impact

The Empik for Woocommerce plug‑in fails to verify a user’s privileges before executing the empik_csv_process_emp_log_classes AJAX handler. An authenticated user who has a subscriber role or higher can exploit this gap to update any product’s metadata, including logistic class, product state, and export flags, effectively allowing the attacker to alter product behavior, availability, or shipping parameters. This represents a CWE‑862 improper authorization flaw where access control is insufficient.

Affected Systems

All installations of the Empik for Woocommerce plug‑in on WordPress from its initial release through version 1.5.1 are affected. The plug‑in can be found as empik:Empik for Woocommerce and is used by e‑commerce sites that rely on WooCommerce integration.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating a medium severity. Its EPSS score is below 1%, suggesting that active exploitation is currently rare. The plug‑in is not listed in the CISA KEV catalog, so no widespread exploitation is reported. Attackers need only be logged in with at least a subscriber role and to trigger the vulnerable AJAX action; no additional capabilities or user‑role escalation are required. While the chance of exploitation is low, the damage to product data integrity can be significant for affected stores.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Empik for Woocommerce to the latest version that includes the authorization check for empik_csv_process_emp_log_classes.
  • If an upgrade is not possible, deactivate the plug‑in or block the Ajax endpoint using a custom filter or security plugin that denies access to non‑administrator users.
  • Implement an additional capability check in the model handling CSV uploads: allow only users with the 'manage_options' or 'administrator' role to call empik_csv_process_emp_log_classes.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Empik
Empik empik For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Empik
Empik empik For Woocommerce
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.
Title Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Empik Empik For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:19.217Z

Reserved: 2026-05-27T20:11:53.364Z

Link: CVE-2026-9766

cve-icon Vulnrichment

Updated: 2026-09-19T13:48:58.948Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:35.210

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:10Z

Weaknesses