Sceawere
Vulnerability Detail
CVE-2026-96817UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MakeCommerce Subscriber Broken Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- MakeCommerce.net
- Product
- MakeCommerce for WooCommerce
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-30T13:17:31.047Z",
"pubdate": "2026-09-30T13:17:31.047Z",
"executiveSummary": "The MakeCommerce for WooCommerce plugin, specifically versions 4.1.0 and below, contains a critical broken access control vulnerability. This security flaw stems from insufficient authorization checks within the plugin's administrative or restricted functional modules.\nThe vulnerability type is categorized as Broken Access Control, allowing authenticated users with low-privileged roles, such as Subscribers, to invoke functions or access data intended strictly for administrators or higher-privileged accounts.\nThe impact is significant, potentially leading to unauthorized configuration changes, sensitive data exposure, or the manipulation of plugin settings. The attack vector is remote, requiring only a valid subscriber-level account to execute requests against the affected plugin endpoints.\nThis vulnerability highlights a failure in the application's authorization logic, where server-side checks do not adequately validate the user's role against the requested action. Organizations using the affected versions are at risk of unauthorized administrative actions, which can be leveraged to further compromise the WordPress environment.",
"technicalDetails": "The root cause of the vulnerability resides in the implementation of the MakeCommerce for WooCommerce plugin's request handling mechanisms. In versions 4.1.0 and earlier, the plugin fails to enforce proper capability checks (e.g., current_user_can('manage_options')) on specific AJAX actions or REST API endpoints designed for administrative plugin configuration.\nThe attack flow initiates when an authenticated user with a 'Subscriber' role crafts a malicious HTTP request targeting the plugin's registered AJAX handlers or restricted backend endpoints. Because the vulnerable functions rely on flawed or non-existent nonce verification and capability checks, the plugin process executes the requested administrative command on behalf of the attacker.\nThe vulnerable component involves the internal routing or hook registration logic within the MakeCommerce codebase. When an attacker sends a request to the plugin's endpoint, the lack of a mandatory privilege check allows the backend process to bypass standard WordPress access control layers. This enables the attacker to interact with plugin settings, potentially modifying payment gateway configurations, API keys, or logging parameters.\nThe exploitation method involves mapping the plugin's available AJAX actions—often found in the plugin's primary JS files or backend PHP registration hooks—and systematically testing them with a lower-privileged session token. Once a sensitive function is identified that lacks adequate access control, an attacker can trigger this function via a simple HTTP POST request, including the necessary action parameter.\nNetwork exposure is defined by the public-facing nature of WordPress AJAX endpoints, meaning the attack can be performed from any remote location provided the attacker has successfully authenticated as a subscriber. Post-exploitation impact may include the redirection of payment flows, exfiltration of transactional logs, or the configuration of the plugin to intercept sensitive customer data. Because the system assumes the user has the right to interact with the plugin's settings, it fails to log these as unauthorized access attempts, complicating forensic detection. The reliance on subscriber-level access implies that any user registration feature enabled on the site significantly lowers the bar for exploitation, making this a high-risk vector in environments that allow open registration."
}