PT-2026-24588 · Undefined · Undefined
Khaled Alenazi
·
Publicado
2026-03-11
·
Atualizado
2026-03-26
·
CVE-2026-2631
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Datalogics Ecommerce Delivery WordPress plugin versions prior to 2.6.60
Description
The Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60 has an unauthenticated REST endpoint that allows remote users to modify the
datalogics token option without authentication. This token is then used to authenticate requests to a protected endpoint, enabling arbitrary WordPress update option() operations. An attacker can leverage this to enable registration and set the default user role to Administrator. The affected plugin exposes an unauthenticated REST endpoint. The vulnerable parameter is datalogics token.Recommendations
Update the Datalogics Ecommerce Delivery WordPress plugin to version 2.6.60 or later.
Exploit
Correção
LPE
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Undefined