Broken Access Control in Abdurrab5 Online Makeup Store Affects User Authorization
CVE-2026-96603
What is CVE-2026-96603?
A vulnerability has been identified in the Abdurrab5 online makeup store, specifically within the Admin Handler's confirm_logged_in/confirm_user function located in functions.php. This vulnerability stems from improper argument handling of the adminid parameter, leading to potential missing authorization checks. Attackers may exploit this flaw remotely, allowing unauthorized access to user accounts and sensitive functions. Despite the absence of disclosed version information due to the product's rolling release system, it is crucial for users to be vigilant and implement necessary security measures to mitigate potential risks.
Affected Version(s)
online-makeup-store 336a4b09e5c840bdfe6dfde6616add0b20e4b4ee
online-makeup-store c3ca96769c008a8a1518c8f9adbc7c8b52d83480
online-makeup-store f804fe3ef5cf3570ced0fa34fb2de492a1306345
