OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-32578

HIGH · CVSS 7.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

ECPay Ecommerce for WooCommerce versions up to 1.1.2606090 are vulnerable to broken access control, allowing unauthorized users to access restricted subscriber functionalities. This flaw could lead to data exposure or manipulation, significantly impacting the security of customer information and transactions. E-commerce operators using affected versions should prioritize remediation to protect their systems and customer data.

CVE
CVE-2026-32578
Severity
HIGH
CVSS
7.1
EPSS
0.31%

Original NVD Description

Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.