CVE-2026-86591
Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.
| Vendor | unknown |
| Product | botiga pro |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown botiga pro
Be the first to know when new unknown vulnerabilities affecting unknown botiga pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Botiga Pro
0 < 1.6.5
References
Credits
Erwan LR (WPScan) WPScan