Junglewise Threat Intelligence

CVE-2026-9766: Empik for Woocommerce authorization bypass

CVE-2026-9766 · Severity: medium · CVSS 4.3 · Published 2026-09-19

Executive brief

The Empik for Woocommerce WordPress plugin fails to properly authorize user actions, allowing lower-privileged authenticated users to modify product metadata. An attacker with subscriber-level access can alter product logistics classes, state flags, and export settings across the entire store without restriction. This could lead to product data corruption, incorrect shipping classifications, or disruption of the e-commerce operation.

Technical details

The plugin lacks proper capability verification in its administrative AJAX endpoints, allowing authenticated users to escalate privileges and modify sensitive WooCommerce product metadata (_empik_logistic_klass, _empik_product_state, _empik_product_state_all_variants, and export flags). The vulnerability requires authentication and affects all versions up to 1.5.1; a fix is available in versions above 1.5.1.

Affected products

  • Empik Empik for Woocommerce up to and including 1.5.1

Timeline

  • 2026-09-19: disclosed

References