CVE-2026-66466: WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
Affected Software
1 affected component
WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart<=2.1.1
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2026-66466?
CVE-2026-66466 is a Broken Access Control vulnerability in the StoreGrowth: Smart Sales Booster for WooCommerce plugin versions up to 2.1.1.
2
What is the severity of CVE-2026-66466?
CVE-2026-66466 has a high severity rating of 7.5.
3
How do I fix CVE-2026-66466?
To address CVE-2026-66466, update the StoreGrowth: Smart Sales Booster for WooCommerce plugin to a version beyond 2.1.1.
4
What are the potential risks of CVE-2026-66466?
CVE-2026-66466 can lead to unauthorized access and manipulation of sensitive functionality within the plugin.
5
Is CVE-2026-66466 exploitable without authentication?
Yes, CVE-2026-66466 is specifically an unauthenticated Broken Access Control vulnerability.