CVE-2026-2631
Datalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.
| Vendor | unknown |
| Product | datalogics ecommerce delivery |
| Published | Mar 11, 2026 |
| Last Updated | Mar 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown datalogics ecommerce delivery
Be the first to know when new critical vulnerabilities affecting unknown datalogics ecommerce delivery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Datalogics Ecommerce Delivery
0 < 2.6.60
References
Credits
Khaled Alenazi (Nxploited) WPScan