CVE-2026-9766
Received Received - Intake

Authorization Bypass in Empik for WooCommerce Plugin

Vulnerability report for CVE-2026-9766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: Wordfence

Description

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
empik woocommerce_plugin to 1.5.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Empik for Woocommerce plugin for WordPress has an authorization bypass vulnerability in versions up to 1.5.1. This flaw allows authenticated users with subscriber-level access or higher to modify product metadata without proper permission checks.

Detection Guidance

To detect this vulnerability, check for unauthorized modifications to WooCommerce product metadata fields like _empik_logistic_klass, _empik_product_state, or _empik_product_state_all_variants. Review WordPress user roles with subscriber access or higher for suspicious activity. Inspect plugin versions to confirm if Empik for WooCommerce is 1.5.1 or lower.

Impact Analysis

An attacker could change product details like logistic class, product state, or export flags. This could disrupt store operations, misrepresent products, or affect order fulfillment without requiring admin access.

Compliance Impact

This vulnerability allows unauthorized modification of product metadata, which could lead to incorrect data handling or exposure. For GDPR, this may impact data integrity and confidentiality requirements. For HIPAA, unauthorized changes to product-related data could affect compliance with secure data management practices.

Mitigation Strategies

Update the Empik for Woocommerce plugin to the latest version beyond 1.5.1 to ensure proper authorization checks are in place.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart