Junglewise Threat Intelligence

CVE-2026-18346: TikTok for Business WordPress plugin authorization bypass

CVE-2026-18346 · Severity: medium · CVSS 5.3 · Published 2026-09-19

Executive brief

The TikTok for Business plugin for WordPress fails to properly verify user permissions, allowing unauthenticated attackers to hijack the site's TikTok Business integration. An attacker with a valid OAuth code can overwrite the stored access token and take control of the site's TikTok product catalog and business account integration. This could lead to unauthorized modification of product listings, disruption of e-commerce operations, or theft of business data.

Technical details

The plugin lacks authorization checks when processing TikTok OAuth token exchanges, allowing unauthenticated users to call the token exchange endpoint. An attacker must possess a valid TikTok OAuth auth_code issued for the merchant's registered app; the plugin will overwrite the stored access token in wp_options if the TikTok API returns a success response. This grants the attacker full control over the site's TikTok Business account integration without requiring user interaction or authentication.

Affected products

  • TikTok TikTok for Business up to 1.4.1

Timeline

  • 2026-09-19: disclosed

References