CVE-2026-27330

8.6

Weptile · Mobile App for WooCommerce

A critical broken access control vulnerability exists in the Mobile App for WooCommerce plugin, allowing unauthenticated attackers to bypass authorization checks.

Executive summary

The Mobile App for WooCommerce plugin contains an unauthenticated broken access control vulnerability that permits unauthorized data access and potential integrity compromise.

Vulnerability

The plugin suffers from a missing authorization flaw (CWE-862), which allows unauthenticated remote attackers to perform unauthorized actions within the WooCommerce environment. This is a network-based vulnerability that requires no user interaction to execute.

Business impact

Successful exploitation of this vulnerability poses a significant risk to e-commerce operations. By bypassing access controls, an attacker may gain unauthorized access to sensitive customer data, order information, or potentially modify store settings, leading to reputational damage and financial loss. With a CVSS score of 8.6, this vulnerability is classified as high severity due to the ease of exploitation and the potential for unauthorized data access.

Remediation

Immediate Action: Update the Mobile App for WooCommerce plugin to version 0.4.63 or higher immediately to resolve the missing authorization flaw.

Proactive Monitoring: Review web server access logs for anomalous requests to plugin endpoints, particularly those originating from unauthorized IP addresses or showing unexpected patterns of data retrieval.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests targeting WooCommerce plugin API endpoints until the update can be applied.

Exploitation status

Public Exploit Available: No confirmed public exploit exists in the available data.

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated access to sensitive store data, this vulnerability represents an urgent security risk. Administrators must prioritize updating the Mobile App for WooCommerce plugin to the latest patched version to effectively neutralize the threat. Failure to patch may expose the application to unauthorized data access and manipulation.

Sources

Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.