PT-2026-33264 · Imprintnext · Riaxe Product Customizer
Kai Aizen
·
Published
2026-04-16
·
Updated
2026-04-16
·
CVE-2026-3595
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/delete customer without a permission callback, causing WordPress to default to allowing unauthenticated access, and the inkxe delete customer() callback function taking an array of user IDs from the request body and passing each one directly to wp delete user() without any authentication or authorization checks. This makes it possible for unauthenticated attackers to delete arbitrary WordPress user accounts, including administrator accounts, leading to complete site lockout and data loss.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Riaxe Product Customizer