Junglewise Threat Intelligence

CVE-2026-65453: motov.net Ebook Store broken access control

CVE-2026-65453 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Motov.Net Ebook Store. Vendors: Motov.Net.

Executive brief

The Ebook Store plugin for WordPress, which allows site owners to sell and manage digital books, contains a security flaw in its access control mechanisms. An unauthenticated remote attacker can exploit this to perform unauthorized actions that should be restricted to administrators. While the impact is considered moderate, it could allow unauthorized changes to the store's configuration or data.

Technical details

The Ebook Store plugin for WordPress (versions 6.19 and below) suffers from a broken access control vulnerability categorized as missing authorization (CWE-862). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient nonce checks before executing certain functions. A remote, unauthenticated attacker can exploit this by sending crafted network requests to the affected site. This allows the attacker to perform actions that are intended for higher-privileged users, potentially modifying plugin settings or data. The issue is resolved in version 6.20.

Affected products

  • motov.net Ebook Store <= 6.19

Timeline

  • 2026-01-25: other: Reported by Nabil Irawan
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References

Related threats