What is CVE-2026-12736?
The Wpify Woo plugin for WordPress up to version 5.4.16 contains a Privilege Escalation vulnerability via its REST route. Unauthenticated attackers can exploit the `SettingsApi::save_option()` function to pass unsanitized parameters to `update_option()`, gaining administrative access. Immediate update to the latest version is strongly advised.
Azərbaycanca: WordPress üçün Wpify Woo plugin-inin 5.4.16-ya qədər versiyalarında "Privilege Escalation" zəifliyi aşkar edilib. REST API üzərindən göndərilən parametrlər yoxlanılmadığı üçün autentifikasiyasız istifadəçilər `update_option()` vasitəsilə admin səlahiyyətləri əldə edə bilər. Plugin-i dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of the Wpify Woo plugin are affected by CVE-2026-12736?
Versions of the Wpify Woo plugin for WordPress up to 5.4.16 are affected by this vulnerability.
What level of access can an attacker gain by exploiting CVE-2026-12736?
An unauthenticated attacker can gain administrative access by passing unsanitized parameters to the `update_option()` function via the REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.