Missing Authorization in Storegrowth Sales Booster Plugin for WordPress
CVE-2026-13110
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-13110?
The Storegrowth Sales Booster plugin for WordPress suffers from a vulnerability due to a missing capability check in its AJAX handler, specifically in the bogo_category_msg_create() function. This function is accessible to both authenticated and unauthenticated users, resulting in potential unauthorized modifications to the BOGO category-message configuration. The exploitation is feasible because the AJAX handler only validates a nonce that can be publicly accessed via frontend pages, enabling unauthenticated attackers to manipulate data stored in the spsg_bogo_general_settings option by sending crafted requests.
Affected Version(s)
StoreGrowth β Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce 0 <= 2.1.0