CVE-2026-18346: TikTok <= 1.4.1 - Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter

Published Sep 19, 2026
·
Updated

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the merchant's stored TikTok integration access token in wpoptions, hijacking the site's TikTok Business and product catalog integration. Successful exploitation requires the attacker to supply a valid TikTok OAuth authcode issued for the merchant's registered TikTok app, as the plugin's token exchange must receive a message='OK' response from TikTok's API before the stored access token is overwritten.

Affected Software

1 affected component
WordPress TikTok plugin<=1.4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TikTok plugin for WordPress to a version that resolves this vulnerability.

    Fixed in 1.4.1
  2. Compensating control

    Restrict access to any WordPress endpoints that perform TikTok OAuth token exchange so only authenticated/authorized users (authorized to manage the merchant’s TikTok integration) can trigger the overwriting of the stored TikTok access token in wp_options.

  3. Operational

    Because unauthenticated attackers may have overwritten the merchant's stored TikTok integration access token in wp_options, rotate/reissue the TikTok integration credentials and confirm wp_options has the expected token value for the merchant’s registered TikTok app.

Event History

Sep 19, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker obtain to exploit this issue?

The attacker must supply a valid TikTok OAuth auth_code issued for the merchant's registered TikTok app. The plugin overwrites the stored token only if TikTok's API token exchange returns message='OK'.

2

What can an attacker change after successful exploitation?

An unauthenticated attacker can overwrite the TikTok integration access token stored in WordPress wp_options. This can hijack the site's TikTok Business and product catalog integration.

3

Are unauthenticated attackers affected by any authorization requirement in WordPress?

No. The authorization bypass allows unauthenticated attackers to perform the token-overwrite action, provided they meet the separate requirement for a valid OAuth auth_code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203