CVE-2026-96817: WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Affected Software
1 affected component
MakeCommerce MakeCommerce for WooCommerce<=4.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MakeCommerce for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 4.1.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as affecting Subscriber-level users. The CVSS vector indicates no privileges or user interaction are required, and it can be exploited over the network.
2
Which versions are affected?
MakeCommerce for WooCommerce versions up to and including 4.1.0 are affected.
3
What is the potential impact?
Successful exploitation can result in integrity impact and limited availability impact. The provided CVSS vector indicates no confidentiality impact.