๐Ÿ” CVE Alert

CVE-2026-86591

UNKNOWN 0.0

Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.

Vendor unknown
Product botiga pro
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown botiga pro

Be the first to know when new unknown vulnerabilities affecting unknown botiga pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Botiga Pro
0 < 1.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e2389a60-16c2-4750-b85e-a82b91390b30/

Credits

Erwan LR (WPScan) WPScan