CVE-2026-86591

NONE EPSS 0.18%
Updated Sep 19, 2026
Unknown
Parameter Value
Affected Versions before 1.6.5
Type CWE-862 Missing Authorization
Vendor Unknown
Public PoC No

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.

Vulnerable Products

unknown:botiga pro