Missing Authorization Vulnerability in Bayarcash WooCommerce by Web Impian
CVE-2026-106609
7.5HIGH
What is CVE-2026-106609?
A significant vulnerability exists in the Bayarcash WooCommerce plugin, which is due to missing authorization controls. This flaw allows unauthorized users to exploit incorrectly configured access control security levels, potentially leading to unauthorized access and manipulation of sensitive data. The affected versions include all prior to 4.4.2, creating a risk for users who have not updated their plugins. Website owners are strongly advised to review their access control settings and ensure they are not exposed to unnecessary risks.
Affected Version(s)
Bayarcash WooCommerce 0 <= 4.4.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Ba Khanh - HPT Vietnam Corporation | Patchstack Bug Bounty Program