Executive brief
The Ibtana Ecommerce Product Addons WordPress plugin fails to properly verify user permissions on a specific AJAX function, allowing authenticated users with basic subscriber-level access to modify or delete metadata associated with any post. An attacker could abuse this to alter product information, prices, or plugin settings without authorization.
Technical details
The 'iepa_use_gt_editor' AJAX action lacks a capability check, permitting any authenticated user to modify post meta via the 'iepa_builder' key. The vulnerability requires authentication (minimum Subscriber role) and network access to the WordPress installation. Attackers can arbitrarily update or delete post metadata, potentially compromising product data integrity and plugin configuration.
Affected products
- Ibtana Ecommerce Product Addons up to and including 0.4.7.7
Timeline
- 2026-09-19: disclosed