Junglewise Threat Intelligence

CVE-2026-49065: Hippoo Mobile App for WooCommerce broken access control

CVE-2026-49065 · Severity: high · CVSS 8.2 · Published 2026-06-15

Technologies: Hippoo Mobile App for WooCommerce. Vendors: Hippoo.

Executive brief

The Hippoo Mobile App for WooCommerce plugin for WordPress, which helps store owners manage their online shops via mobile, contains a security flaw that allows unauthorized individuals to access restricted data or perform actions without logging in. This could lead to the exposure of sensitive customer or store information and potentially disrupt business operations. Store owners should update to version 1.9.6 immediately to secure their sites.

Technical details

The Hippoo Mobile App for WooCommerce plugin for WordPress (versions <= 1.9.5) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw by sending crafted requests to the affected site, bypassing intended security restrictions. This allows the attacker to perform actions or access data that should be restricted to administrative users. The vulnerability is rated with a CVSS score of 8.2, reflecting high confidentiality impact. A fix is available in version 1.9.6.

Affected products

  • Hippoo Hippoo Mobile App for WooCommerce <= 1.9.5

Timeline

  • 2026-06-03: other: Reported by researcher manop55555
  • 2026-06-08: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-06-08: patched: Version 1.9.6 released to address the vulnerability

References

Related threats