Junglewise Threat Intelligence

CVE-2026-86591: Botiga Pro WordPress plugin unauthenticated REST authorization bypass

CVE-2026-86591 · Severity: critical · CVSS 9.8 · Published 2026-09-19

Executive brief

Botiga Pro is a WordPress plugin that provides website design and template building features. A flaw in its REST API endpoints allows attackers without authentication to modify site settings, inject malicious scripts that run on all pages, and delete posts—potentially giving them complete control of the website. This could enable ransomware deployment, data theft, or defacement.

Technical details

The plugin fails to validate user authorization on a REST route used by its Templates Builder functionality. An unauthenticated attacker can exploit this via network requests to modify arbitrary WordPress options, store and execute arbitrary JavaScript on the front end, and move posts to trash. The vulnerability requires no user interaction and affects versions before 1.6.5.

Affected products

  • Botiga Botiga Pro before 1.6.5

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: patched: Fixed in version 1.6.5

References