CVE-2026-92404
MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
| Vendor | unknown |
| Product | mgosync |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mgosync
Be the first to know when new unknown vulnerabilities affecting unknown mgosync are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / MgoSync
2.1.5 < 2.1.7
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan