Executive brief
The Ebook Store plugin for WordPress, which allows site owners to sell and manage digital books, contains a security flaw in its access control mechanisms. An unauthorized user could exploit this vulnerability to access information or perform actions that should be restricted to administrators. This could lead to the exposure of sensitive store data or unauthorized changes to the ebook management system.
Technical details
The Ebook Store plugin for WordPress is vulnerable to broken access control in versions up to and including 6.19. The vulnerability stems from a missing authorization check (CWE-862) in certain plugin functions, allowing an unauthenticated remote attacker to execute actions or access data that should require higher privileges. The attack can be carried out over the network without any user interaction. The issue is resolved in version 6.20.
Affected products
- motov.net Ebook Store <= 6.19
Timeline
- 2026-01-23: other: Reported by researcher benzdeus
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD