Sceawere

Vulnerability Detail

CVE-2026-105878UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authorization in YITH WooCommerce Product Bundles

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
YITH
Product
YITH WooCommerce Product Bundles
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-08T13:17:13.187Z",
  "pubdate": "2026-10-08T13:17:13.187Z",
  "executiveSummary": "YITH WooCommerce Product Bundles versions n/a through 2.29.0 are susceptible to a Missing Authorization vulnerability.\nThe vulnerability originates from incorrectly configured access control security levels within the plugin's architectural framework.\nThis flaw permits unauthorized actors to perform actions that are intended to be restricted based on user role or permission settings.\nThe impact includes potential unauthorized access to sensitive plugin-related data, functions, or configurations that should otherwise remain protected.\nAttackers can leverage this vulnerability to manipulate product bundle settings or perform unauthorized operations without requiring legitimate administrative or elevated privileges.\nThe risk is significant as it facilitates unauthorized interactions with the plugin's backend functionality, potentially leading to unauthorized data modification or administrative bypass.\nNo specific mention of exploitation complexity is provided, but the lack of authorization checks fundamentally undermines the security posture of the affected WooCommerce product management ecosystem.",
  "technicalDetails": "The vulnerability is rooted in an inadequate implementation of authorization checks within the YITH WooCommerce Product Bundles plugin, specifically affecting versions 2.29.0 and earlier.\nThe plugin fails to adequately validate the privileges of the requester before executing sensitive actions. In the context of web application security, this implies that the application's access control mechanisms do not properly enforce security constraints, allowing unauthenticated or low-privileged users to invoke functions restricted to administrative or authorized roles.\nThe attack flow typically involves an attacker identifying the endpoint or the internal function call responsible for performing privileged actions within the YITH WooCommerce Product Bundles plugin. Because the plugin does not verify the security context—such as user capabilities or nonce verification—the server processes the request as if it originated from an authorized user.\nBy crafting a malicious request or interacting directly with the vulnerable API or backend function, an attacker can bypass the intended access restrictions. This is a classic case of broken access control, where the security boundary between different user roles is effectively erased.\nThe exploitation does not necessarily require the attacker to possess elevated credentials. If the endpoint is exposed, any user with network connectivity to the web server can trigger these operations. The lack of proper authorization validation means the application relies on client-side security assumptions or implicit trust, which is insufficient for preventing unauthorized access.\nPost-exploitation, the attacker may gain the ability to alter product configurations, manage bundle components, or interact with other administrative functions provided by the plugin. The impact depends on the specific functions exposed through the insecure endpoints, but broadly, it results in the loss of integrity for the affected WooCommerce store's product management data.\nThe vulnerable component essentially neglects to implement checks such as 'current_user_can()' or equivalent WordPress permission validation primitives. Consequently, any request sent to the affected URI is processed without verifying if the user has the requisite authority, leading to unauthorized state changes or data leakage within the product bundle management system."
}
CVE-2026-105878: Missing Authorization in YITH WooCommerce Product Bundles (MEDIUM Severity, CVSS: 5.3) | Sceawere