PT-2026-97608 · Abdurrab5 · Online-Makeup-Store

·

CVE-2026-96603

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Abdurrab5 online-makeup-store (affected versions not specified)
Description An authorization bypass exists in the Admin Handler component within the functions.php file. A remote attacker can manipulate the adminid argument in the confirm logged in() and confirm user() functions to gain unauthorized access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the confirm logged in() and confirm user() functions in the functions.php file to minimize the risk of exploitation.

Exploit

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96603

Affected Products

Online-Makeup-Store