WordPress · Tiktok Plugin For Wordpress · CVE-2026-18346
**Name of the Vulnerable Software and Affected Versions**
TikTok plugin for WordPress versions prior to 1.4.2
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to overwrite the merchant's stored TikTok integration access token within `wp options`, enabling the hijacking of the site's TikTok Business and product catalog integration. To exploit this, an attacker must provide a valid TikTok OAuth `auth code` issued for the merchant's registered TikTok app, as the plugin requires a `message='OK'` response from the TikTok API before the access token is updated.
**Recommendations**
Update the TikTok plugin for WordPress to version 1.4.2 or later.