Junglewise Threat Intelligence

CVE-2026-59554: Ziina WordPress plugin broken authentication

CVE-2026-59554 · Severity: high · CVSS 7.5 · Published 2026-07-23

Executive brief

The Ziina plugin for WordPress, which facilitates payment processing, contains a security flaw that allows unauthorized users to bypass authentication. This could allow an attacker to perform administrative actions or gain full control over the website. Such access could lead to the theft of customer data, site defacement, or the disruption of payment services.

Technical details

The Ziina plugin for WordPress (versions <= 1.2.21) suffers from a broken authentication vulnerability (CWE-1390). The flaw allows an unauthenticated remote attacker to bypass security checks and perform actions that should be restricted to high-privileged users. According to the advisory, this can be leveraged to gain administrative access to the affected WordPress site. The vulnerability is exploited over the network without requiring user interaction. A fix is available in version 1.2.22.

Affected products

  • Ziina Ziina <= 1.2.21

Timeline

  • 2026-05-18: disclosed: Reported by Mitchell to Patchstack
  • 2026-07-22: advisory: Patchstack published the vulnerability details
  • 2026-07-23: patched: NVD published the CVE record; patch available in version 1.2.22

References