Executive brief
The Empik for Woocommerce WordPress plugin fails to properly authorize user actions, allowing lower-privileged authenticated users to modify product metadata. An attacker with subscriber-level access can alter product logistics classes, state flags, and export settings across the entire store without restriction. This could lead to product data corruption, incorrect shipping classifications, or disruption of the e-commerce operation.
Technical details
The plugin lacks proper capability verification in its administrative AJAX endpoints, allowing authenticated users to escalate privileges and modify sensitive WooCommerce product metadata (_empik_logistic_klass, _empik_product_state, _empik_product_state_all_variants, and export flags). The vulnerability requires authentication and affects all versions up to 1.5.1; a fix is available in versions above 1.5.1.
Affected products
- Empik Empik for Woocommerce up to and including 1.5.1
Timeline
- 2026-09-19: disclosed