Sceawere
Vulnerability Detail
CVE-2026-88828UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Blacklist Manager Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- Unknown
- Product
- Blacklist Manager
- Attack Type
- CWE-288 Authentication Bypass Using an Alternate Path or Channel
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-28T07:17:21.063Z",
"pubdate": "2026-09-28T07:17:21.063Z",
"executiveSummary": "The Blacklist Manager for WooCommerce plugin is susceptible to an authentication bypass vulnerability affecting versions 1.3.0 through 2.3.1. This flaw stems from incomplete enforcement of user account blocking mechanisms across all authentication vectors.\nThe vulnerability allows an account holder who has been explicitly blocked by a site administrator to maintain access and continue performing authorized operations. Because the blocking logic is not globally verified during session initialization or authentication request processing, the plugin fails to terminate active sessions or prevent subsequent logins for restricted users.\nThe impact is significant, as it permits unauthorized access by prohibited individuals, effectively rendering the administrative block feature ineffective. This poses a severe risk to data integrity and system security, particularly in e-commerce environments where account restriction is a primary defense against malicious actors, compromised accounts, or suspended users. No specialized privileges are required beyond the possession of valid credentials for an account that has been marked as blocked within the application.\nExploitation is trivial and does not require advanced technical capabilities, as the attacker simply continues utilizing their existing credentials to interact with the system despite the administrative block status.",
"technicalDetails": "The core of this vulnerability lies in an inconsistent implementation of access control logic within the Blacklist Manager for WooCommerce plugin. The plugin fails to instantiate a comprehensive check of the user's block status at critical junctures of the WordPress authentication flow. Specifically, while the plugin may apply blocking logic to primary login forms or specific hooks, it fails to sanitize or validate the user status across alternative authentication paths or background session refreshes.\nThe root cause is identified as an incomplete hook or conditional check implementation where the authorization state is not re-verified against the blacklist database during non-standard authentication requests. Consequently, when a user is flagged in the blacklist, the metadata or flag indicating the blocked status is ignored by the authentication sub-routines. This creates a state where the WordPress authentication system validates the password and user ID but fails to query the secondary validation logic provided by the Blacklist Manager.\nThe attack flow follows a predictable pattern: 1) A site administrator identifies a suspicious or prohibited user and updates the user's status to 'blocked' within the Blacklist Manager plugin. 2) The plugin correctly updates the internal database entry or user meta. 3) The blocked user, possessing valid credentials, initiates a new authentication request or continues interacting with the system through an existing session. 4) Because the authentication path used by the user does not trigger the plugin's validation logic, the WordPress authentication system completes the user login process.\nThis behavior persists across multiple session states. The user is able to bypass the restrictive measures, effectively maintaining their account privileges. The lack of an 'on-every-request' or 'on-authentication-flow' validation gate means the system does not recognize the account as restricted. Post-exploitation, the user retains the ability to perform any action permitted by their role, including unauthorized purchases, profile modifications, or access to sensitive customer data, depending on the role assigned to the compromised account.\nThis vulnerability is present in all versions from 1.3.0 to 2.3.1. The flaw is not restricted to a specific network topology; it is exploitable over any protocol where the affected authentication path is accessible, including standard HTTP/HTTPS channels commonly used for WordPress site management and front-end interaction."
}