UNKNOWN NVD

CVE-2026-92404

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.

References

Published: 2026-09-19 · Source: NVD · Feed updated: 2026-09-19
This unknown severity vulnerability was published on 2026-09-19 via NVD.
vulnfeed aggregates 14156 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.