Junglewise Threat Intelligence

CVE-2026-49060: Hippoo Mobile App for WooCommerce privilege escalation

CVE-2026-49060 · Severity: critical · CVSS 9.8 · Published 2026-06-11

Technologies: Hippoo Mobile App for WooCommerce. Vendors: Hippoo.

Executive brief

The Hippoo Mobile App for WooCommerce plugin, which allows store owners to manage their online shops via mobile, contains a critical security flaw. This vulnerability allows an unauthorized person to gain administrative access to the website. Once exploited, an attacker can take full control of the online store, potentially leading to the theft of customer data, site defacement, or complete service disruption.

Technical details

An incorrect privilege assignment vulnerability (CWE-266) exists in the Hippoo Mobile App for WooCommerce plugin for WordPress. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the affected WordPress site. The vulnerability stems from improper validation of user roles or permissions within the plugin's mobile integration components. Attackers can exploit this over the network without any user interaction. A fix is available in version 1.9.5.

Affected products

  • Hippoo Hippoo Mobile App for WooCommerce n/a through 1.9.4

Timeline

  • 2026-05-29: other: Reported by ParkHyunWoo
  • 2026-06-08: advisory: Patchstack advisory published
  • 2026-06-11: disclosed: NVD publication date

References

Related threats