{"id":"CVE-2026-86591","published":"2026-09-19T07:16:33.063","lastModified":"2026-09-21T13:34:57.127","description":"The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover.\nThe same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/e2389a60-16c2-4750-b85e-a82b91390b30/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows unauthenticated users to update WordPress options and store executable scripts, leading to potential full site takeover and privilege escalation.","exploitability":"Exploitation is straightforward as no authentication is required, and the affected route is accessible to any user.","blast_radius":"If exploited, the impact could be severe, potentially leading to complete control over the WordPress site.","remediation":"Upgrade to version 1.6.5 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:00:19.306Z"}}