CVE-2026-81428
Received Received - Intake

WC Vendors IDOR in Product Variations

Vulnerability report for CVE-2026-81428, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status and title of arbitrary posts, via IDOR.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wc_vendors wc_vendors to 2.7.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the WC Vendors WordPress plugin before version 2.7.2.1. It allows authenticated users with the vendor role to modify product variations and posts belonging to other vendors without verifying ownership. The flaw stems from not validating user-supplied IDs properly.

Detection Guidance

Check if your WC Vendors plugin version is below 2.7.2.1. Log in as a vendor and attempt to modify product variations or posts owned by other vendors. Monitor for unauthorized changes to product status, titles, or post ownership.

Impact Analysis

An attacker with vendor access could change product details, alter post statuses, or modify titles of posts they do not own. This could disrupt store operations, misrepresent products, or cause data inconsistencies on the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized data modifications, potentially violating integrity and access control requirements in GDPR and HIPAA. Unauthorized changes to product or post data may result in non-compliance with data protection and security standards.

Mitigation Strategies

Update the WC Vendors plugin to version 2.7.2.1 or later immediately. Review logs for suspicious activity by vendor accounts. Restrict vendor permissions to the minimum required. Apply the latest security patches for WordPress and all plugins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81428. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart