Executive brief
The Social Commerce for WooCommerce WordPress plugin fails to validate user permissions on certain REST API endpoints, allowing attackers without any credentials to modify plugin settings and synchronization status. An attacker exploiting this could alter how products are synced to Facebook, disrupting ecommerce operations or causing data inconsistency.
Technical details
CWE-862: Missing authorization checks on REST API endpoints allow unauthenticated network access to modify plugin configuration and product synchronization state. The vulnerability affects versions through 2.5.4 with no known patch available. Exploitation requires only network access and no authentication or user interaction.
Affected products
- Skynet Innovations Social Commerce for WooCommerce through 2.5.4
Timeline
- 2026-09-20: disclosed
- 2026-09-23: advisory