PT-2026-95758 · WordPress · Botiga Pro

·

CVE-2026-86591

·

Published

2026-09-19

·

Updated

2026-09-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Botiga Pro versions prior to 1.6.5
Description Lack of authorization checks on a REST route allows unauthenticated users to update arbitrary WordPress options with arbitrary values. This can lead to privilege escalation and full site takeover. Additionally, the same route enables unauthenticated users to store arbitrary web scripts that execute on every page of the site front end and move arbitrary posts to the trash.
Recommendations Update Botiga Pro to version 1.6.5 or later.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86591

Affected Products

Botiga Pro