CVE-2026-81794
nicheUnauthenticated Broken Access Control in Shirt Product Designer for WooCommerce
CVE-2026-81794 is a broken access control flaw (CWE-862, missing authorization) in the Shirt Product Designer for WooCommerce WordPress plugin, in which a privileged action is reachable without any authentication check. An unauthenticated attacker triggers it by sending a crafted network request directly to the affected endpoint, since the code performs the action without verifying user privileges or intent. Per the CVSS vector (Network, Low complexity, No privileges, No user interaction, Integrity impact High), a successful attack lets the attacker modify data on the site, such as plugin or store data, without reading or disrupting it. Any WordPress/WooCommerce site running the disclosed affected version (1.0.4) of the plugin is in scope; the available data does not specify the exact fixed release. There is no public proof of concept, the CVE is not in CISA's KEV, and no exploitation has been observed to date.
What to do: Update Shirt Product Designer for WooCommerce to the latest patched release as soon as one is published, and check the vendor/WordPress.org changelog for the fixed version number. Until patched, consider disabling the plugin if it is not essential, or blocking unauthenticated requests to the plugin's endpoints via a WAF or web server rules. Review the site for unexplained modifications to product, order, or plugin settings, since the flaw's primary impact is unauthorized data changes.
| Shirt Product Designer for WooCommerce (WordPress plugin) Shirt Product Designer for WooCommerce | 1.0.4 (as disclosed; exact affected/fixed version range not further specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.