CVE-2026-88828
Received
Received - Intake
Authentication Bypass in Blacklist Manager for WooCommerce
Vulnerability report for CVE-2026-88828, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-28
Last updated on: 2026-09-28
Assigner: WPScan
Description
Description
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| woocommerce | blacklist_manager | From 1.3.0 (inc) to 2.3.1 (inc) |
| woocommerce | blacklist_manager | 2.3.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |