CVE-2026-2631
Last modified
CVE-2026-2631 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-2631?
How severe is CVE-2026-2631?
How do I fix CVE-2026-2631?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26304Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail …4.3
- CVE-2026-26305The WebSocket Application Programming Interface lacks restri…9.8
- CVE-2026-26306The installer for OM Workspace (Windows Edition) Ver 2.4 and…8.4
- CVE-2026-26307Gitea versions before 1.25.5 do not enforce a timeout on git…7.5
- CVE-2026-26308Envoy is a high-performance edge/middle/service proxy. Prior…8.2
- CVE-2026-26309Envoy is a high-performance edge/middle/service proxy. Prior…5.3
- CVE-2026-26310Envoy is a high-performance edge/middle/service proxy. Prior…7.5
- CVE-2026-26311Envoy is a high-performance edge/middle/service proxy. Prior…5.9
- CVE-2026-26312Stalwart is a mail and collaboration server. A denial-of-ser…6.5
- CVE-2026-26313go-ethereum (geth) is a golang execution layer implementatio…7.5
- CVE-2026-26314go-ethereum (geth) is a golang execution layer implementatio…7.5
- CVE-2026-26315go-ethereum (Geth) is a golang execution layer implementatio…7.5
Are you affected by CVE-2026-2631?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
