Junglewise Threat Intelligence

CVE-2026-42664: Motive Commerce Search for WooCommerce broken access control

CVE-2026-42664 · Severity: high · CVSS 8.2 · Published 2026-06-15

Executive brief

A security vulnerability exists in the Motive Commerce Search plugin for WooCommerce, which provides AI-powered product search functionality for online stores. An unauthorized attacker can bypass security checks to perform actions they should not be allowed to access. This could lead to unauthorized changes to the search configuration or disruptions to the store's search availability, potentially impacting customer experience and sales.

Technical details

The Motive Commerce Search plugin for WooCommerce (versions up to and including 1.38.2) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions that should be restricted to administrative users. According to the CVSS vector, the primary impact is on integrity and availability, suggesting an attacker could modify settings or cause a denial of service within the plugin's functionality. The issue is resolved in version 1.38.3.

Affected products

  • Motive Commerce Search AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2

Timeline

  • 2026-04-09: other: Reported by researcher Benedictus Jovan
  • 2026-05-09: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-05-09: patched: Version 1.38.3 released to address the issue

References