Junglewise Threat Intelligence

CVE-2026-61958: Saad Iqbal License Manager for WooCommerce missing authorization

CVE-2026-61958 · Severity: medium · CVSS 5.4 · Published 2026-07-13

Vendors: Saad Iqbal.

Executive brief

A security vulnerability exists in the License Manager for WooCommerce plugin, which is used by online stores to manage and distribute software licenses. Due to incorrect access controls, an authenticated user with low-level permissions could potentially delete content they should not have access to. This could lead to service disruptions or the loss of important licensing data within the store's management system.

Technical details

The License Manager for WooCommerce plugin (versions up to and including 3.0.17) contains a Missing Authorization vulnerability (CWE-862). The flaw stems from incorrectly configured access control security levels within the plugin's management interface. An attacker authenticated with low-level privileges (such as a subscriber or customer) can exploit this lack of authorization to perform actions beyond their intended scope, specifically resulting in arbitrary content deletion. The issue is resolved in version 3.0.18.

Affected products

  • Saad Iqbal License Manager for WooCommerce <= 3.0.17

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: disclosed
  • 3.0.18: patched

References