CVE-2026-24606: WordPress Bayarcash WooCommerce plugin <= 4.3.13 - Broken Access Control vulnerability
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through <= 4.3.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24606?
CVE-2026-24606 is classified as a medium-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-24606?
To fix CVE-2026-24606, update the Bayarcash WooCommerce plugin to a version later than 4.3.11.
What specific issue does CVE-2026-24606 address?
CVE-2026-24606 addresses a Broken Access Control vulnerability that allows unauthorized exploitation due to incorrectly configured access levels.
Who is affected by CVE-2026-24606?
CVE-2026-24606 affects WordPress sites using the Bayarcash WooCommerce plugin version 4.3.11 or earlier.
Can CVE-2026-24606 lead to data breaches?
Yes, CVE-2026-24606 could potentially lead to data breaches as it allows unauthorized users to access restricted areas of the application.