CRITICAL
9.8 CVE-2026-86591 Published 19 Sept 2026
Botiga Pro WordPress Plugin Missing Authorization Allows Site Takeover
Worried this affects your website?
The Botiga Pro WordPress plugin before 1.6.5 contains a missing authorization vulnerability in one of its REST routes.
Because the route lacks authorization checks, unauthenticated users can exploit it to:
- Update arbitrary WordPress options with arbitrary values, potentially leading to privilege escalation and full site takeover.
- Store arbitrary web scripts that are executed on every page of the site's front end.
- Move arbitrary posts to arbitrary locations.
Reference: CVE-2026-86591 on NVD
← Back to Security News