What is CVE-2026-13110?
A critical Missing Authorization vulnerability in the Storegrowth Sales Booster plugin for WordPress up to version 2.1.0. The flaw exists in the bogo_category_msg_create() AJAX handler, which lacks proper capability checks, potentially allowing unauthenticated attackers to perform unauthorized actions. Immediate update to the latest plugin version is recommended.
Azərbaycanca: WordPress üçün Storegrowth Sales Booster plagininin 2.1.0 və aşağı versiyalarında müəyyən edilmiş kritik zəiflikdir. Bu boşluq bogo_category_msg_create() AJAX funksiyası üzərində icazə yoxlamasının olmaması səbəbindən autentifikasiya olunmamış hücumçulara da daxil olmaqla, icazəsiz əməliyyatlar aparmağa imkan verir. Dərhal plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Storegrowth Sales Booster plugin are affected by CVE-2026-13110?
The Storegrowth Sales Booster plugin for WordPress versions 2.1.0 and below are affected by this critical vulnerability.
What is the root cause of the CVE-2026-13110 vulnerability?
The root cause is a Missing Authorization flaw in the bogo_category_msg_create() AJAX handler, which lacks proper capability checks and can allow unauthenticated attackers to perform unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.