Executive brief
Product Catalog Enquiry for WooCommerce is a WordPress plugin that allows store operators to manage customer inquiries about products. An unauthenticated attacker can exploit an incorrect privilege assignment flaw to gain administrator access to the WooCommerce site, enabling full control over the store, customer data, and transactions.
Technical details
The plugin contains an incorrect privilege assignment vulnerability that permits unauthenticated users to escalate privileges to administrator. The flaw allows a low-privilege or unauthenticated attacker to bypass authorization checks and assume admin role, gaining full control over the WordPress installation. No patch is currently available; mitigation via WAF rules is recommended.
Affected products
- MultiVendorX Product Catalog Enquiry for WooCommerce through 6.1.5
Timeline
- 2026-09-07: disclosed
- 2026-09-08: advisory