Sceawere
Vulnerability Detail
CVE-2026-105421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authorization in Kit WooCommerce
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- Kit
- Product
- Kit (formerly ConvertKit) for WooCommerce
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T15:17:21.043Z",
"pubdate": "2026-10-05T15:17:21.043Z",
"executiveSummary": "The Kit (formerly ConvertKit) for WooCommerce plugin is susceptible to a Missing Authorization vulnerability, which exposes administrative functions to unauthorized users. This flaw exists due to incorrectly configured access control checks within the plugin's architecture, allowing malicious actors to perform actions that should be restricted to privileged administrative accounts.\nThe vulnerability affects versions n/a through 2.2.0. Impact includes the potential for unauthorized data modification, unauthorized configuration changes, or the execution of sensitive plugin-specific operations without the necessity of authenticated administrative sessions.\nThis vulnerability poses a significant security risk, as it allows unauthenticated or low-privileged attackers to interact with internal API endpoints or administrative handlers. The primary implication is the compromise of the integrity and configuration of the WooCommerce integration, potentially leading to unauthorized data exfiltration or site instability. Exploitation typically requires access to the target web server's environment where the vulnerable plugin is active, and no complex interaction is required beyond triggering the specifically crafted request to the vulnerable endpoint.",
"technicalDetails": "The root cause of this vulnerability lies in the failure of the plugin to properly enforce access control mechanisms on critical hooks or REST API endpoints. In the architecture of the Kit for WooCommerce plugin, specific functions responsible for plugin configuration or background data synchronization fail to validate the user's authorization level prior to executing sensitive operations.\nWhen a user or a malicious actor sends a request to the vulnerable endpoint, the application fails to verify the current session's permissions, such as checking for the 'manage_options' capability or confirming the user possesses administrative privileges. Consequently, the request is processed as if it originated from a trusted source.\nThe attack flow proceeds as follows: 1) An attacker identifies the exposed administrative function or endpoint within the plugin's codebase. 2) The attacker crafts a request, such as an HTTP POST or GET request, targeting this specific endpoint. 3) Because of the missing authorization check, the server-side code executes the logic associated with the function without checking if the requester is an administrator. 4) The plugin performs the unauthorized action—which could involve updating mailing list settings, modifying API keys, or triggering unauthorized synchronization tasks—effectively bypassing the WordPress access control model.\nThis vulnerability is classified as an authorization bypass. The vulnerable component is likely a class or method within the plugin that handles incoming administrative requests without invoking standard WordPress authentication or capability verification functions such as 'current_user_can()'.\nAffected versions are identified from n/a through 2.2.0. The vulnerability is persistent and exposes the plugin to external manipulation across all environments running the specified versions. Post-exploitation impact varies depending on the specific function triggered by the attacker; however, the ability to modify plugin settings could facilitate further attacks, such as redirecting customer data to attacker-controlled external services or disabling core marketing synchronization features.\nThe vulnerability does not necessarily require the attacker to be authenticated as an administrator; in many instances of missing authorization, the endpoint may be reachable by any visitor, depending on how the plugin registers its actions with the WordPress hooks system. The network exposure is limited to the public-facing URL of the WordPress installation running the vulnerable plugin, making it trivial for an automated scanner to detect and exploit."
}