Junglewise Threat Intelligence

CVE-2026-57419: Fahad Mahmood Stock Locations for WooCommerce missing authorization

CVE-2026-57419 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

A security vulnerability exists in the Stock Locations for WooCommerce plugin, which is used by online stores to manage inventory across multiple physical locations. An attacker with a basic user account could bypass security checks to modify stock information or settings they should not have access to. This could lead to incorrect inventory data, potentially disrupting sales and store operations.

Technical details

The Stock Locations for WooCommerce plugin for WordPress is vulnerable to Broken Access Control (CWE-862) in versions up to and including 3.1.8. The vulnerability stems from missing authorization checks in functions that handle stock location data or settings. An attacker authenticated as a low-privileged user (such as a Subscriber) can perform actions that should be restricted to higher-privileged roles, specifically allowing for unauthorized integrity changes to the site's data. The issue is addressed in version 3.1.9.

Affected products

  • Fahad Mahmood Stock Locations for WooCommerce <= 3.1.8

Timeline

  • 2026-05-29: disclosed: Reported by Mitchell to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-13: patched: Version 3.1.9 released to address the issue

References