CVE-2026-13110: StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogocategorymsgcreate() AJAX handler, which is registered for both authenticated (wpajax) and unauthenticated (wpajaxnopriv) users and only validates a nonce ('ajdprotected') that is emitted publicly via wplocalizescript() on every frontend page through frontscripts() . This makes it possible for unauthenticated attackers to modify the plugin's BOGO category-message configuration stored in the spsgbogogeneralsettings option by reading the nonce from any public page and POSTing attacker-controlled data to admin-ajax.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13110?
The severity of CVE-2026-13110 is rated as medium with a score of 5.3.
What type of vulnerability is CVE-2026-13110?
CVE-2026-13110 is a Missing Authorization vulnerability affecting the StoreGrowth plugin.
How do I fix CVE-2026-13110?
To fix CVE-2026-13110, update the StoreGrowth plugin to version 2.1.1 or later.
Which versions of the StoreGrowth plugin are affected by CVE-2026-13110?
CVE-2026-13110 affects versions of the StoreGrowth plugin up to and including 2.1.0.
What is the impact of CVE-2026-13110?
The impact of CVE-2026-13110 allows unauthenticated users to modify plugin settings, leading to potential site compromise.