CRITICAL
9 CVE-2026-88795 Published 17 Sept 2026
WordPress wpShopGermany Plugin Auth Token Predictability Bug
Worried this affects your website?
The wpShopGermany WordPress plugin, versions prior to 2.4, has a critical security flaw. It generates API authentication tokens insecurely, using data controlled by the requester, allowing unauthenticated attackers to predict these tokens.
Exploiting this vulnerability enables attackers to gain unauthorized access and write arbitrary files, leading to potential remote code execution.
Reference: CVE-2026-88795 on NVD
← Back to Security News