CVE-2026-86850
SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
| Vendor | unknown |
| Product | sku error fixer for woocommerce |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown sku error fixer for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown sku error fixer for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SKU Error Fixer for WooCommerce
0 โค 1.0
References
Credits
Naoki Kawahigashi WPScan