CVE-2026-106609: WordPress Bayarcash WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Bayarcash WooCommerce pluginto a version that resolves this vulnerability.Fixed in 4.4.3
Event History
Frequently Asked Questions
Which deployments are affected?
Bayarcash WooCommerce versions through 4.4.2 are affected. The available data does not identify a fixed version.
Can this be exploited remotely without an account?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely security impact?
The stated impact is integrity loss, with no reported confidentiality or availability impact. The issue is described as missing authorization caused by incorrectly configured access-control security levels.