LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-10580

Published
CVSS9.8
Severitycritical
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_access() unconditionally interprets as full administrator access — causing override_extension_permission_callback() to assign __return_true as the permission callback for every WordPress and WooCommerce REST route cloned under /wc-hippoo/v1/ext/ by HippooControllerWithAuth::re_register_external_routes()

References

← Back to the CVE Tracker

Our coverage of CVE-2026-10580

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-10580.