Sceawere

Vulnerability Detail

CVE-2026-39794UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Access in WooCommerce Multivendor

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
16h ago
Vendor
WC Lovers
Product
WooCommerce Multivendor Marketplace – REST API
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T09:17:52.387Z",
  "pubdate": "2026-10-06T09:17:52.387Z",
  "executiveSummary": "The WooCommerce Multivendor Marketplace plugin is susceptible to an unauthenticated broken access control vulnerability within its REST API endpoints, affecting versions 1.6.3 and below.\nThis vulnerability allows remote, unauthenticated attackers to interact with restricted API functionalities that should require administrative or vendor-level privileges.\nThe security flaw stems from inadequate authorization checks on specific REST API routes, enabling unauthorized data access, modification, or potential administrative actions depending on the specific endpoint exposed.\nThe risk implication is significant, as it bypasses standard WordPress authentication mechanisms, granting attackers unauthorized visibility into marketplace operations, vendor data, or sensitive customer information.\nNo specific user interaction or pre-existing account is required for exploitation, significantly lowering the barrier for entry for malicious actors.\nGiven the nature of marketplace plugins, this could lead to widespread data leakage, unauthorized order manipulation, or the compromise of vendor store configurations.",
  "technicalDetails": "The vulnerability resides within the REST API controller implementation of the WooCommerce Multivendor Marketplace plugin. The root cause is the absence of sufficient capability checks (e.g., current_user_can()) or nonce validation within the endpoint registration callbacks for the affected API routes.\nIn the WordPress REST API, developers must explicitly define 'permission_callback' functions when registering routes to ensure that only authorized users can perform requested operations. In affected versions (<= 1.6.3), these callbacks are either missing, incorrectly configured, or fail to validate the authentication status of the incoming request.\nThe attack flow begins with the attacker identifying the plugin-specific REST API endpoints. Since these endpoints are exposed by default, the attacker can send unauthorized HTTP requests (GET, POST, PUT, DELETE) to the REST API server. Because the plugin fails to verify the session or role of the requester, the API handler executes the requested functionality as if the user were authorized.\nThe attack involves the following steps: 1. Mapping the REST API endpoints provided by the WooCommerce Multivendor Marketplace plugin. 2. Crafting a malicious request aimed at sensitive endpoints that manage vendor profiles, orders, or commission settings. 3. Sending the request without authentication headers or with irrelevant credentials. 4. The server processes the request because the vulnerable code skips the authorization check, returning the sensitive data or executing the unintended action.\nThis vulnerability is particularly critical due to the sensitive nature of marketplace data. An attacker could potentially extract sensitive vendor financial information, list hidden products, or modify vendor payment details to redirect funds. Because the REST API is accessible over the network, this vulnerability is globally exploitable from any remote location, provided the target site is reachable via HTTP/HTTPS.\nThe impact is magnified because the plugin often functions with elevated permissions to manage multiple vendor accounts simultaneously. A successful exploit can lead to total compromise of the integrity and confidentiality of the marketplace data, effectively bypassing the security model of the WooCommerce ecosystem."
}
CVE-2026-39794: Unauthenticated Access in WooCommerce Multivendor (HIGH Severity, CVSS: 7.5) | Sceawere