Authorization Bypass Vulnerability in TikTok Plugin for WordPress
CVE-2026-18346
5.3MEDIUM
What is CVE-2026-18346?
The TikTok plugin for WordPress contains a vulnerability that allows unauthenticated users to bypass authorization checks. This flaw exists in all versions prior to 1.4.1, enabling attackers to overwrite the merchant's TikTok integration access token stored in wp_options. To exploit this vulnerability, the attacker must provide a valid TikTok OAuth auth_code, which is issued for the merchant's registered TikTok application. The plugin incorrectly processes the token exchange, requiring only a message='OK' response from TikTok's API to initiate the overwrite, exposing sensitive API integration details to potential intruders.
Affected Version(s)
TikTok 0 <= 1.4.1