{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-86785", "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "state": "PUBLISHED", "assignerShortName": "WPScan", "dateReserved": "2026-09-08T11:49:45.537Z", "datePublished": "2026-09-23T06:00:13.845Z", "dateUpdated": "2026-09-23T11:02:03.589Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "shortName": "WPScan", "dateUpdated": "2026-09-23T06:00:13.845Z" }, "title": "Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update", "problemTypes": [ { "descriptions": [ { "description": "CWE-862 Missing Authorization", "lang": "en", "type": "CWE" } ] } ], "affected": [ { "vendor": "Unknown", "product": "Social Commerce for WooCommerce", "versions": [ { "status": "affected", "versionType": "semver", "version": "0", "lessThanOrEqual": "2.5.4" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state." } ], "references": [ { "url": "https://wpscan.com/vulnerability/9a4c36bd-c7f7-4068-ac73-b29ee66def96/", "tags": [ "exploit", "vdb-entry", "technical-description" ] } ], "credits": [ { "lang": "en", "value": "Pablo González", "type": "finder" }, { "lang": "en", "value": "Fran Ramirez and Iñigo Sánchez", "type": "finder" }, { "lang": "en", "value": "WPScan", "type": "coordinator" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "WPScan CVE Generator" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-862", "lang": "en", "description": "CWE-862 Missing Authorization" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-23T10:43:41.027335Z", "id": "CVE-2026-86785", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-23T11:02:03.589Z" } } ] } }