Authorization Bypass Vulnerability in StoreGrowth's WooCommerce Plugin
CVE-2026-15411

5.3MEDIUM

What is CVE-2026-15411?

The StoreGrowth Smart Sales Booster for WooCommerce plugin is susceptible to an authorization bypass, allowing unauthenticated attackers to exploit the system. The flaw arises from the plugin's inadequate verification of user permissions, particularly utilizing the 'ajd_protected' nonce, which is exposed on the frontend. This weakness enables attackers to overwrite the 'spsg_popup_products' option with malicious data, compromising the integrity of the site’s operations and potentially leading to further exploitation.

Affected Version(s)

StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce 0 <= 2.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.