Junglewise Threat Intelligence

CVE-2026-39705: Mulika Team MIPL WC Multisite Sync missing authorization

CVE-2026-39705 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The MIPL WC Multisite Sync plugin for WordPress, which synchronizes WooCommerce data across multiple sites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels due to missing authorization checks. An attacker could potentially modify site configurations or data without permission, though the overall impact on data confidentiality is considered low.

Technical details

A missing authorization vulnerability (CWE-862) exists in the MIPL WC Multisite Sync plugin through version 1.4.4. The flaw stems from a failure to properly validate user permissions or security tokens (nonces) before executing sensitive functions. An unauthenticated remote attacker can exploit this to perform actions that should be restricted to higher-privileged users. According to the CVSS vector, the impact is limited to partial integrity loss with no impact on confidentiality or availability. No official patch has been confirmed in the primary advisory text, though some sources suggest versions up to 1.4.8 may be affected.

Affected products

  • Mulika Team MIPL WC Multisite Sync <= 1.4.4

Timeline

  • 2026-01-30: other: Vulnerability reported by researcher Legion Hunter
  • 2026-03-01: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References