PT-2026-94171 · WordPress · Wpshopgermany It-Recht Kanzlei

·

CVE-2026-88795

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpShopGermany IT-RECHT KANZLEI versions prior to 2.4
Description The plugin fails to generate API authentication tokens securely. The token is derived from data controlled by the requester and is created as a side effect of the validation check. This allows unauthenticated attackers to predict the token and use the resulting access to write arbitrary files, which can lead to remote code execution.
Recommendations Update to version 2.4 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88795

Affected Products

Wpshopgermany It-Recht Kanzlei