ZeroHour

CVE-2026-81794

niche

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81794 is a broken access control flaw (CWE-862, missing authorization) in the Shirt Product Designer for WooCommerce WordPress plugin, in which a privileged action is reachable without any authentication check. An unauthenticated attacker triggers it by sending a crafted network request directly to the affected endpoint, since the code performs the action without verifying user privileges or intent. Per the CVSS vector (Network, Low complexity, No privileges, No user interaction, Integrity impact High), a successful attack lets the attacker modify data on the site, such as plugin or store data, without reading or disrupting it. Any WordPress/WooCommerce site running the disclosed affected version (1.0.4) of the plugin is in scope; the available data does not specify the exact fixed release. There is no public proof of concept, the CVE is not in CISA's KEV, and no exploitation has been observed to date.

What to do: Update Shirt Product Designer for WooCommerce to the latest patched release as soon as one is published, and check the vendor/WordPress.org changelog for the fixed version number. Until patched, consider disabling the plugin if it is not essential, or blocking unauthenticated requests to the plugin's endpoints via a WAF or web server rules. Review the site for unexplained modifications to product, order, or plugin settings, since the flaw's primary impact is unauthorized data changes.

Affected
Shirt Product Designer for WooCommerce (WordPress plugin) Shirt Product Designer for WooCommerce1.0.4 (as disclosed; exact affected/fixed version range not further specified in available data)
Estimated exposure
nichelikely low thousands of WordPress sites or fewer (niche WooCommerce extension; no active-install count available) — No active-install statistics were provided; product-designer extensions for WooCommerce are typically low-volume plugins, so exposure is estimated at the niche level rather than mass market.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.