CVE-2026-88795
wpShopGermany · IT-RECHT KANZLEI
The wpShopGermany IT-RECHT KANZLEI plugin before 2.4 allows unauthenticated attackers to predict API tokens and perform remote code execution through improper authentication token generation.
Executive summary
A critical vulnerability in the wpShopGermany IT-RECHT KANZLEI plugin allows unauthenticated remote code execution, posing a severe risk to site integrity and server security.
Vulnerability
The plugin suffers from improper authentication token generation, where tokens are derived from user-controlled input during validation. This flaw allows unauthenticated attackers to predict valid tokens and leverage them to write arbitrary files, resulting in remote code execution.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the underlying server. This could lead to a complete compromise of the WordPress environment, unauthorized access to sensitive customer data, and potential lateral movement within the hosting infrastructure. With a CVSS score of 9.0, this issue is classified as critical, necessitating immediate attention to prevent full system takeover.
Remediation
Immediate Action: Update the wpShopGermany IT-RECHT KANZLEI plugin to version 2.4 or later immediately to resolve the token generation flaw.
Proactive Monitoring: Review web server access logs for suspicious requests directed toward the plugin API endpoints, particularly those originating from unauthorized or unknown IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting the plugin API until the update can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity of this vulnerability and the potential for remote code execution, organizations must prioritize patching the affected plugin across all WordPress instances. Failure to update to version 2.4 leaves the site vulnerable to unauthenticated attackers who can gain full control of the application. Perform the update immediately and verify the integrity of the server environment to ensure no unauthorized files have been introduced.
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.0 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Naoki Kawahigashi, with WPScan (coordinator), per the CVE Program record.