Loading market data...
← Back to CVE feed

CVE-2026-88828

MEDIUM CVSS 5.4 View on NVD ↗

Description

The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: Sep 28, 2026 07:17 UTC Modified: Sep 28, 2026 16:38 UTC