CVE-2026-86591

CVE-2026-86591 published: The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full...

View full NVD advisory → ← Back to CVE watch