Unauthenticated Insecure Direct Object Reference in Simple Shopping Cart by WordPress
CVE-2026-48868

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-48868?

The Insecure Direct Object Reference (IDOR) vulnerability allows unauthenticated users to access sensitive resources or manipulate data through direct access to objects within the Simple Shopping Cart plugin. This flaw exists in versions 5.2.9 and earlier, potentially permitting compromised transactions or unauthorized access to user account information. Implementing security measures and regular updates to the plugin can mitigate these risks.

Affected Version(s)

Simple Shopping Cart <= 5.2.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Austin Ginder | Patchstack Bug Bounty Program
.