OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-39794

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The WooCommerce Multivendor Marketplace REST API versions up to 1.6.3 are vulnerable to unauthenticated broken access control, allowing attackers to exploit the API without authentication. This could lead to unauthorized access to sensitive data or functionality, potentially compromising the integrity of the marketplace. E-commerce platforms utilizing this plugin should prioritize patching this vulnerability to protect against potential exploitation.

CVE
CVE-2026-39794
Severity
HIGH
CVSS
7.5
EPSS
N/A

Original NVD Description

Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.