๐Ÿ” CVE Alert

CVE-2026-2631

CRITICAL 9.8

Datalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.

Vendor unknown
Product datalogics ecommerce delivery
Published Mar 11, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown datalogics ecommerce delivery

Be the first to know when new critical vulnerabilities affecting unknown datalogics ecommerce delivery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Datalogics Ecommerce Delivery
0 < 2.6.60

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c6a64f26-4007-49a1-aa69-1e3c50223ac7/

Credits

Khaled Alenazi (Nxploited) WPScan