CVE-2026-9766 - Empik for Woocommerce = 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action
Brief
CVE ID : CVE-2026-9766
Published : Sept. 19, 2026, 9:16 a. m.
- 11 hours, 40 minutes ago
Description : The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.
- 1. This is due to the plugin not properly verifying that a user is authorized to perform an action.
This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.
Severity: 4.3
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
