Access Control Flaw in Hyyan WooCommerce Polylang Integration Plugin
CVE-2026-24585
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 January 2026
What is CVE-2026-24585?
A missing authorization vulnerability exists in the Hyyan WooCommerce Polylang Integration plugin, allowing unauthorized access due to incorrectly configured access control security levels. This flaw affects versions up to and including 1.5.0, posing a risk of unauthorized manipulation and exposure of sensitive information.
Affected Version(s)
Hyyan WooCommerce Polylang Integration 0 <= 1.5.0