OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-92404

HIGH · CVSS 7.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The MgoSync WordPress plugin prior to version 2.1.7 lacks proper authorization controls on a REST API endpoint, enabling unauthenticated users to access sensitive WooCommerce API credentials, including read/write consumer keys and secrets. This vulnerability poses a significant risk as it could lead to unauthorized access and manipulation of e-commerce data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-92404
Severity
HIGH
CVSS
7.5
EPSS
0.43%
WordPress

Original NVD Description

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.