CVE-2026-66466 HIGH

CVE-2026-66466: WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability

Vendor Wedevs
Product StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
Weakness CWE-862 · Missing authorization
Published August 13, 2026
Last update August 13, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

StoreGrowth for WooCommerce versions up to 2.1.1 lack proper authorization checks, allowing unauthenticated attackers to modify store data without permission. An attacker can change product information, pricing, or other critical settings by sending direct requests to the plugin. No user interaction or special access is required. Site owners should update immediately to a patched version.

What an attacker can do

03Attacker Capabilities

Modify store data, pricing, or product settings without logging in.

Potential impact on your site

04Site Impact

Attackers can alter product prices, descriptions, or other store configuration without your knowledge or consent.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE