CRITICAL 9.8 CVE-2026-86591 Published 19 Sept 2026

Botiga Pro WordPress Plugin Missing Authorization Allows Site Takeover

Worried this affects your website?

The Botiga Pro WordPress plugin before 1.6.5 contains a missing authorization vulnerability in one of its REST routes.

Because the route lacks authorization checks, unauthenticated users can exploit it to:

  • Update arbitrary WordPress options with arbitrary values, potentially leading to privilege escalation and full site takeover.
  • Store arbitrary web scripts that are executed on every page of the site's front end.
  • Move arbitrary posts to arbitrary locations.

Reference: CVE-2026-86591 on NVD

← Back to Security News