VYPR
Vypr IntelligenceAI-generatedAug 18, 2026· 7 CVEs

Webkul Bagisto: Seven Vulnerabilities Including XSS and Auth Bypass Disclosed Together

Seven vulnerabilities affecting Webkul Bagisto (up to v2.4.4) were disclosed together, including XSS, auth bypass, and privilege issues, with some exploits publicly available.

Key findings

  • Seven vulnerabilities disclosed together for Webkul Bagisto versions up to 2.4.4.
  • Flaws include Cross-Site Scripting (XSS), Authorization Bypass, and Privilege Management issues.
  • Multiple vulnerabilities affect the RMA (Return Merchandise Authorization) system.
  • Exploits for several CVEs are publicly available, increasing immediate risk.
  • The disclosure spans customer registration, backend administration, and configuration management components.

On August 17-18, 2026, a batch of seven vulnerabilities was disclosed for Webkul Bagisto, affecting versions up to 2.4.4. These vulnerabilities, ranging in severity from Low to Medium, were reported together, indicating a coordinated disclosure event. The issues primarily impact customer registration, RMA (Return Merchandise Authorization) handling, and backend administrative functions, with several allowing for remote exploitation.

Several vulnerabilities center around the RMA system. CVE-2026-75081 and CVE-2026-19993, both rated Medium, involve the enforcement of behavioral workflows within the RMA process. Specifically, CVE-2026-75081 affects the /customer/account/rma/store endpoint, while CVE-2026-19993 targets the /customer/account/rma/update-status component. Additionally, CVE-2026-19995, a Low severity Cross-Site Scripting (XSS) vulnerability, impacts the RMA message handler at /customer/account/rma/send-message.

Cross-Site Scripting (XSS) is also present in the customer registration module. CVE-2026-75082, a Medium severity flaw, affects the /customer/register file, allowing manipulation of the first_name and last_name arguments to execute arbitrary scripts.

Authorization bypass vulnerabilities were also disclosed. CVE-2026-19994, a Medium severity issue with a CVSS score of 6.3, targets the Configuration Management component at /admin/configuration/cache-management/execute, allowing an attacker to bypass authorization by manipulating the action argument. Another authorization bypass, CVE-2026-19997 (Medium severity), affects the Backend Sales RMA Endpoint at /admin/sales/rma/requests.

Privilege management is also a concern, with CVE-2026-19996 (Medium severity) identified in the Backend Customer Behavior Data Endpoint at /admin/customers. Manipulation of the ID argument in this component can lead to improper privilege management.

The disclosures indicate that exploits for several of these vulnerabilities are publicly available, including CVE-2026-75081, CVE-2026-19997, CVE-2026-19996, and CVE-2026-19995. This increases the risk for unpatched systems. All disclosed vulnerabilities affect Webkul Bagisto versions up to 2.4.4. Users are advised to update to a patched version to mitigate these risks.

The coordinated disclosure of these seven vulnerabilities highlights potential weaknesses across multiple facets of the Bagisto platform, from customer-facing registration and support to backend administrative functions. The presence of publicly available exploits for several of these issues underscores the urgency for administrators to apply patches. Continued vigilance and prompt application of security updates are crucial for maintaining the integrity of Bagisto installations.

AI-written article. Grounded in 7 CVE records listed below.