PT-2026-24588 · Undefined · Undefined

Khaled Alenazi

·

Publicado

2026-03-11

·

Atualizado

2026-03-26

·

CVE-2026-2631

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Datalogics Ecommerce Delivery WordPress plugin versions prior to 2.6.60
Description The Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60 has an unauthenticated REST endpoint that allows remote users to modify the datalogics token option without authentication. This token is then used to authenticate requests to a protected endpoint, enabling arbitrary WordPress update option() operations. An attacker can leverage this to enable registration and set the default user role to Administrator. The affected plugin exposes an unauthenticated REST endpoint. The vulnerable parameter is datalogics token.
Recommendations Update the Datalogics Ecommerce Delivery WordPress plugin to version 2.6.60 or later.

Exploit

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2631

Produtos afetados

Undefined