Broken Access Control in Abdurrab5 Online Makeup Store Affects User Authorization
CVE-2026-96603

6.9MEDIUM

Key Information:

Vendor

Abdurrab5

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96603?

A vulnerability has been identified in the Abdurrab5 online makeup store, specifically within the Admin Handler's confirm_logged_in/confirm_user function located in functions.php. This vulnerability stems from improper argument handling of the adminid parameter, leading to potential missing authorization checks. Attackers may exploit this flaw remotely, allowing unauthorized access to user accounts and sensitive functions. Despite the absence of disclosed version information due to the product's rolling release system, it is crucial for users to be vigilant and implement necessary security measures to mitigate potential risks.

Affected Version(s)

online-makeup-store 336a4b09e5c840bdfe6dfde6616add0b20e4b4ee

online-makeup-store c3ca96769c008a8a1518c8f9adbc7c8b52d83480

online-makeup-store f804fe3ef5cf3570ced0fa34fb2de492a1306345

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yashkumar Keral (VulDB User)
VulDB CNA Team
.