The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover.
The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.
CVE-2026-86591
NONE
EPSS 0.18%
Updated Sep 19, 2026
Unknown
unknown:botiga pro
CVE Details
CVE ID
CVE-2026-86591
Published Date
Sep 19, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
8.2th percentile (higher than 8.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory