Authorization Bypass Vulnerability in StoreGrowth's WooCommerce Plugin
CVE-2026-15411
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15411?
The StoreGrowth Smart Sales Booster for WooCommerce plugin is susceptible to an authorization bypass, allowing unauthenticated attackers to exploit the system. The flaw arises from the plugin's inadequate verification of user permissions, particularly utilizing the 'ajd_protected' nonce, which is exposed on the frontend. This weakness enables attackers to overwrite the 'spsg_popup_products' option with malicious data, compromising the integrity of the site’s operations and potentially leading to further exploitation.
Affected Version(s)
StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce 0 <= 2.1.0