Junglewise Threat Intelligence

CVE-2026-54804: Melhor Envio broken authentication in WordPress plugin

CVE-2026-54804 · Severity: high · CVSS 7.6 · Published 2026-06-17

Executive brief

Melhor Envio is a WordPress plugin used to manage shipping and logistics for e-commerce sites. A security flaw in versions 2.16.3 and earlier allows users with low-level accounts, such as subscribers, to bypass authentication checks. This could allow an attacker to perform unauthorized actions or potentially gain full administrative control over the website, leading to data theft or site defacement.

Technical details

A broken authentication vulnerability (CWE-288) exists in the Melhor Envio plugin for WordPress in versions up to and including 2.16.3. The flaw allows an authenticated attacker with 'Subscriber' level privileges to bypass intended authentication paths or channels. By exploiting this alternate path, a malicious actor can execute functions typically reserved for higher-privileged users, potentially leading to full site takeover. The vulnerability is remediated in version 2.16.4.

Affected products

  • melhorenvio Melhor Envio <= 2.16.3

Timeline

  • 2026-04-29: other: Vulnerability reported by researcher HieuPenguinnn
  • 2026-06-16: disclosed: Advisory published by Patchstack
  • 2026-06-17: advisory: CVE published in NVD
  • 2026-06-17: patched: Patch released in version 2.16.4

References