ZeroHour

CVE-2026-81790

moderate

Missing Authorization in Csomagpontok és szállítási címkék WooCommerce-hez plugin

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-81790 is a missing-authorization flaw (CWE-862) in the WordPress/WooCommerce plugin "Csomagpontok és szállítási címkék WooCommerce-hez" (pickup points and shipping labels) by Viszt Péter, where incorrectly configured access controls allow requests to bypass required permission checks. Because the check is absent for unauthenticated users (CVSS AV:N/PR:N), a remote attacker with no account can invoke the affected plugin functionality over the network. Per the CVSS 3.1 vector, the attacker gains high integrity impact (ability to modify data or settings) with no confidentiality or availability impact. All plugin versions before 4.2.8 are affected, so any WooCommerce shop running an older version is exposed. There is currently no known public PoC, no CISA KEV listing, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (18th percentile), so exploitation is not known to be occurring.

What to do: Update the plugin to version 4.2.8 or later as soon as possible. If immediate patching is not possible, restrict unauthenticated access to the plugin's endpoints (e.g., via WAF rules) and review pickup-point/shipping-label settings and related data for unauthorized changes. No public PoC or in-the-wild exploitation is known, but remediation is straightforward and should be prioritized given the flaw is remotely exploitable without credentials.

Affected
Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez (WordPress/WooCommerce plugin)all versions from n/a before 4.2.8 (fixed in 4.2.8)
Estimated exposure
moderate≈10,000+ WooCommerce sites (est.; regional Hungarian-market plugin) — Estimate based on the plugin being a WordPress.org-distributed WooCommerce extension serving primarily Hungarian online shops, with active installs plausibly in the low tens of thousands; exact install counts were not provided in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.