Junglewise Threat Intelligence

CVE-2026-54846: akosglys Syncee Premium Dropshipping & Wholesale broken access control

CVE-2026-54846 · Severity: high · CVSS 7.5 · Published 2026-06-26

Executive brief

A security vulnerability exists in the Syncee Premium Dropshipping & Wholesale plugin for WordPress, which is used to manage product sourcing and automated fulfillment for e-commerce stores. An unauthenticated attacker can bypass security checks to access sensitive information or perform unauthorized actions. This could lead to the exposure of proprietary business data or disruption of dropshipping operations.

Technical details

The Syncee Premium Dropshipping & Wholesale plugin for WordPress (versions up to and including 1.0.27) is vulnerable to broken access control due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. The issue is resolved in version 1.0.28.

Affected products

  • akosglys Syncee Premium Dropshipping & Wholesale <= 1.0.27

Timeline

  • 2026-06-05: other: Reported by researcher dodoh4t
  • 2026-06-18: advisory: Initial advisory published by Patchstack
  • 2026-06-26: disclosed: CVE published to NVD
  • 2026-06-26: patched: Patch available in version 1.0.28

References