Junglewise Threat Intelligence

CVE-2026-39701: Andrew ShopWP missing authorization in wpshopify plugin

CVE-2026-39701 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The ShopWP plugin for WordPress, which integrates Shopify stores into WordPress sites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to potentially perform actions or access features that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized changes to the store's configuration or data.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Andrew ShopWP (wpshopify) plugin for WordPress through version 5.2.4. The flaw stems from incorrectly configured access control security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this to execute actions that should require higher privileges. According to the advisory, there is currently no official patch available, and the vulnerability is classified as a broken access control issue. The attack vector is network-based with low complexity and requires no user interaction.

Affected products

  • Andrew ShopWP (wpshopify) <= 5.2.4

Timeline

  • 2026-01-30: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-03-01: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References