← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 19, 2026 · 09:16via CVEFeed

CVE-2026-9766 - Empik for Woocommerce = 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action

Brief

CVE ID : CVE-2026-9766

Published : Sept. 19, 2026, 9:16 a. m.

  • 11 hours, 40 minutes ago

Description : The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.

  • 1. This is due to the plugin not properly verifying that a user is authorized to perform an action.

This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.

Severity: 4.3

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→