Junglewise Threat Intelligence

CVE-2026-57649: studiowombat Shoppable Images Lite broken access control

CVE-2026-57649 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Executive brief

Shoppable Images Lite is a WordPress plugin used to create interactive images with clickable product links. A security flaw in versions 1.3 and earlier allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. While the impact is considered low, it could lead to unauthorized data viewing or minor configuration changes depending on the specific functions exposed.

Technical details

A broken access control vulnerability exists in the Shoppable Images Lite plugin for WordPress (versions <= 1.3) due to missing authorization checks (CWE-862) in certain plugin functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this over the network to execute actions or access data intended for higher-privileged users. The vulnerability was addressed in version 1.3.1 by implementing proper permission checks. The exploit requires network reachability to the WordPress site and a valid low-level user account.

Affected products

  • studiowombat Shoppable Images Lite <= 1.3

Timeline

  • 2026-06-09: other: Reported by researcher Ananda Dhakal
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Fixed in version 1.3.1

References