CVE-2026-88828
Last modified
CVE-2026-88828 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded..
Description
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Blacklist Manager | >= 1.3.0, < 2.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-88828?
How severe is CVE-2026-88828?
How do I fix CVE-2026-88828?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8881Version 3.0.7 of the Securly Chrome Extension uses EVP_Bytes…7.5
- CVE-2026-88817An authenticated, non-guest user of Curiosity Workspace coul…8.7
- CVE-2026-88819In Siglet current and past versions the refresh token handle…6.3
- CVE-2026-8882The WP ApplicantStack Jobs Display plugin for WordPress is v…6.4
- CVE-2026-88824The Master Blocks WordPress plugin before 1.5.0 does not ha…8.8
- CVE-2026-88825The iGMS Direct Booking WordPress plugin before 2.0 does not…8.8
- CVE-2026-8883The Global Body Mass Index Calculator plugin for WordPress i…6.4
- CVE-2026-88830A unit confusion in BusyBox TLS Montgomery reduction buffer …7.5
- CVE-2026-88831BusyBox httpd IP deny rules with invalid CIDR prefix lengths…5.3
- CVE-2026-88832BusyBox romfs volume ID parsing uses unbounded strlen on att…7.3
- CVE-2026-88835BusyBox dpkg read_package_field() steps past a NUL terminato…6.1
- CVE-2026-88837BusyBox httpd treats yescrypt ($y$) password hashes as plain…6.5
Are you affected by CVE-2026-88828?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
