CVE-2026-92404: MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: MgoSyncto a version that resolves this vulnerability.Fixed in 2.1.7 - Operational
Assume WooCommerce API consumer key and secret may have been disclosed by unauthenticated access to the MgoSync REST API endpoint; rotate/revoke and replace the exposed WooCommerce API credentials on the configured site.
Event History
Frequently Asked Questions
Which sites are exposed?
Sites using MgoSync versions before 2.1.7 are exposed if the plugin has been configured with WooCommerce API credentials. The affected endpoint lacks authorization controls, so it can be accessed without authentication.
What can an attacker obtain and why does it matter?
An attacker can retrieve the stored WooCommerce consumer key and secret, including credentials with read/write access. Those credentials could allow access to the WooCommerce API with the permissions assigned to the exposed key.
What should be done after updating the plugin?
Update MgoSync to version 2.1.7 or later. Because the previously stored consumer key and secret may already have been disclosed, replace the affected WooCommerce API credentials.