CVE-2026-86850: SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deletion
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The affected AJAX actions are available to unauthenticated users and lack both capability and nonce checks, so an attacker does not need a WordPress account or administrative privileges.
What data or functionality is exposed?
An attacker can obtain details of product variations the plugin classifies as obsolete and can permanently delete those variations. The deletion leaves no recoverable copy behind.
Are default deployments affected?
The available data identifies the issue in the plugin through version 1.0, but does not state whether a particular configuration or workflow is required for variations to be classified as obsolete.