PT-2026-65444 · WordPress · Storegrowth Sales Booster
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Storegrowth Sales Booster versions prior to 2.1.1
Description
Missing authorization in the
bogo category msg create() AJAX handler allows unauthenticated attackers to modify the BOGO category-message configuration stored in the spsg bogo general settings option. The issue occurs because the handler is registered for both authenticated and unauthenticated users and only validates a nonce (ajd protected) that is publicly exposed on every frontend page via wp localize script() through front scripts(). An attacker can read this nonce from any public page and send controlled data to the admin-ajax endpoint.Recommendations
Update Storegrowth Sales Booster to a version newer than 2.1.0.
As a temporary workaround, restrict access to the
admin-ajax endpoint or disable the BOGO category-message functionality until the update is applied.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Storegrowth Sales Booster