Executive brief
Botiga Pro is a WordPress plugin that provides website design and template building features. A flaw in its REST API endpoints allows attackers without authentication to modify site settings, inject malicious scripts that run on all pages, and delete posts—potentially giving them complete control of the website. This could enable ransomware deployment, data theft, or defacement.
Technical details
The plugin fails to validate user authorization on a REST route used by its Templates Builder functionality. An unauthenticated attacker can exploit this via network requests to modify arbitrary WordPress options, store and execute arbitrary JavaScript on the front end, and move posts to trash. The vulnerability requires no user interaction and affects versions before 1.6.5.
Affected products
- Botiga Botiga Pro before 1.6.5
Timeline
- 2026-09-17: disclosed
- 2026-09-19: patched: Fixed in version 1.6.5