SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16569

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WooCommerce Mobile App Builder Service for WordPress is vulnerable due to insufficient capability checks, enabling any authenticated user, including customers and subscribers, to modify stock quantities of any product via its REST endpoints. This flaw could lead to unauthorized inventory manipulation, potentially resulting in financial losses or inventory discrepancies. WordPress site administrators using this plugin should prioritize addressing this vulnerability to safeguard their e-commerce operations.

CVE
CVE-2026-16569
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.