Executive brief
The Hippoo Mobile App for WooCommerce plugin, which allows store owners to manage their online shops via mobile, contains a critical security flaw. This vulnerability allows an unauthorized person to gain administrative access to the website. Once exploited, an attacker can take full control of the online store, potentially leading to the theft of customer data, site defacement, or complete service disruption.
Technical details
An incorrect privilege assignment vulnerability (CWE-266) exists in the Hippoo Mobile App for WooCommerce plugin for WordPress. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the affected WordPress site. The vulnerability stems from improper validation of user roles or permissions within the plugin's mobile integration components. Attackers can exploit this over the network without any user interaction. A fix is available in version 1.9.5.
Affected products
- Hippoo Hippoo Mobile App for WooCommerce n/a through 1.9.4
Timeline
- 2026-05-29: other: Reported by ParkHyunWoo
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-11: disclosed: NVD publication date