Sceawere

Vulnerability Detail

CVE-2026-66466UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StoreGrowth Smart Sales Booster Broken Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
weDevs
Product
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T14:17:07.960Z",
  "pubdate": "2026-08-13T14:17:07.960Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin. This security flaw allows unauthenticated remote attackers to bypass authorization controls and interact with privileged functionality or access restricted data within the WordPress environment. The vulnerability impacts all plugin versions up to and including 2.1.1. Successful exploitation does not require any user interaction, valid user credentials, or specific privilege levels, significantly lowering the attack barrier. The risk implications include unauthorized execution of restricted application logic, potential manipulation of e-commerce data, and state modification depending on the specific endpoints exposed by the insecure access controls. Mitigation requires immediate updates to patched versions once available or disabling the affected plugin functionality until remediation can be applied.",
  "technicalDetails": "The vulnerability stems from improper authorization checks within the request handling lifecycle of the StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin in versions <= 2.1.1. Specifically, backend functionalities, AJAX actions, or REST API endpoints exposed by the plugin fail to adequately verify whether the incoming request originates from an authenticated user possessing the requisite capabilities for the requested operation.\nRoot cause analysis indicates an absence of robust permission validation checks, such as missing calls to current_user_can() or the omission of secure nonces in sensitive execution paths. Because the access control mechanism is either absent or improperly implemented, unauthenticated network-based attackers can directly invoke vulnerable controller methods or action handlers via HTTP requests.\nThe attack flow proceeds as follows: 1) The attacker maps or identifies the exposed endpoints associated with the plugin's features (such as upsell configurations, direct checkout handlers, or quick view routines). 2) The attacker crafts a malicious HTTP request targeting these internal functions without supplying session cookies, authentication tokens, or authorization headers. 3) The vulnerable component processes the incoming parameters without validating the caller's privilege level. 4) The application executes the underlying business logic, returning sensitive data or performing unauthorized state changes on behalf of the unauthenticated entity.\nThe attack vector is network-based, exposing the application to remote exploitation over HTTP/HTTPS protocols. Because the vulnerability requires zero authentication and no privileges, any external entity with network access to the target WordPress site can leverage automated scripts or manual requests to trigger the flawed code paths, leading to potential data exposure or unauthorized functional execution."
}
CVE-2026-66466: StoreGrowth Smart Sales Booster Broken Access Control (HIGH Severity, CVSS: 7.5) - Sceawere