PT-2026-33264 · Imprintnext · Riaxe Product Customizer

Kai Aizen

·

Published

2026-04-16

·

Updated

2026-04-16

·

CVE-2026-3595

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/delete customer without a permission callback, causing WordPress to default to allowing unauthenticated access, and the inkxe delete customer() callback function taking an array of user IDs from the request body and passing each one directly to wp delete user() without any authentication or authorization checks. This makes it possible for unauthenticated attackers to delete arbitrary WordPress user accounts, including administrator accounts, leading to complete site lockout and data loss.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3595

Affected Products

Riaxe Product Customizer