PT-2026-65444 · WordPress · Storegrowth Sales Booster

·

CVE-2026-13110

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Storegrowth Sales Booster versions prior to 2.1.1
Description Missing authorization in the bogo category msg create() AJAX handler allows unauthenticated attackers to modify the BOGO category-message configuration stored in the spsg bogo general settings option. The issue occurs because the handler is registered for both authenticated and unauthenticated users and only validates a nonce (ajd protected) that is publicly exposed on every frontend page via wp localize script() through front scripts(). An attacker can read this nonce from any public page and send controlled data to the admin-ajax endpoint.
Recommendations Update Storegrowth Sales Booster to a version newer than 2.1.0. As a temporary workaround, restrict access to the admin-ajax endpoint or disable the BOGO category-message functionality until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13110

Affected Products

Storegrowth Sales Booster