Junglewise Threat Intelligence

CVE-2026-65456: PickPlugins Product Slider for WooCommerce IDOR in WordPress

CVE-2026-65456 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

The Product Slider for WooCommerce plugin, used to display product carousels on WordPress e-commerce sites, contains a security flaw. An attacker with contributor-level access can bypass intended restrictions to access or interact with data they should not be able to see. While the risk is considered low, it could lead to unauthorized access to sensitive information or database interactions.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the PickPlugins Product Slider for WooCommerce plugin for WordPress in versions up to and including 1.13.62. The flaw is rooted in insufficient authorization checks when handling user-controlled keys or object identifiers. A remote attacker with 'Contributor' or higher privileges can exploit this to bypass access controls, potentially allowing them to view sensitive files or interact with the database in ways not intended by the application. The vulnerability was addressed in version 1.13.63.

Affected products

  • PickPlugins Product Slider for WooCommerce <= 1.13.62

Timeline

  • 2026-06-10: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Patch available in version 1.13.63

References