CyberRota Analysis
AI-GeneratedThe WooCommerce Multivendor Marketplace REST API versions up to 1.6.3 are vulnerable to unauthenticated broken access control, allowing attackers to exploit the API without authentication. This could lead to unauthorized access to sensitive data or functionality, potentially compromising the integrity of the marketplace. E-commerce platforms utilizing this plugin should prioritize patching this vulnerability to protect against potential exploitation.
CVE
CVE-2026-39794
Severity
HIGH
CVSS
7.5
EPSS
N/A
Original NVD Description
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.