PT-2026-24588 · Undefined · Undefined

Khaled Alenazi

·

Published

2026-03-11

·

Updated

2026-03-26

·

CVE-2026-2631

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Datalogics Ecommerce Delivery WordPress plugin versions prior to 2.6.60
Description The Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60 has an unauthenticated REST endpoint that allows remote users to modify the datalogics token option without authentication. This token is then used to authenticate requests to a protected endpoint, enabling arbitrary WordPress update option() operations. An attacker can leverage this to enable registration and set the default user role to Administrator. The affected plugin exposes an unauthenticated REST endpoint. The vulnerable parameter is datalogics token.
Recommendations Update the Datalogics Ecommerce Delivery WordPress plugin to version 2.6.60 or later.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-2631

Affected Products

Undefined