VYPR

Botiga Pro

by WordPress

CVEs (1)

  • CVE-2026-86591Sep 19, 2026
    risk 0.00cvss epss

    The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The…