External risk intelligence

Botiga Pro WordPress Plugin Authorization Bypass Enables Site Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-86591

The vulnerability exists in a WordPress plugin. WordPress sites are web applications commonly deployed as public-facing services, and the affected REST routes are accessible over the network to any visitor, making them likely to be reachable from the internet in common deployments.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Botiga Pro WordPress plugin that could allow unauthenticated users to take control of a website. This issue could enable attackers to escalate privileges, execute malicious scripts across the site, and delete content. The main concern is confirming relevance and exposure of this plugin within our environment.

  • Website plugin allows unauthenticated site takeover.
  • Affects website integrity and user-facing content.
  • Verify plugin usage and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by accessing a specific network path within the Botiga Pro WordPress plugin. Since no authentication is required, any unauthenticated user can interact with this path. This allows them to modify critical site settings, inject malicious scripts that run on every page, or even delete posts, potentially leading to a complete website compromise.

  • Requires no authentication to access.
  • Triggers by making requests to a REST route.
  • Risk includes site takeover and script execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated users can update arbitrary WordPress options, leading to privilege escalation and site takeover. This vulnerability also allows injecting malicious scripts that execute across the entire site's front end, and the deletion of arbitrary posts.

  • Arbitrary WordPress options can be modified.
  • Unauthenticated users can inject scripts.
  • Site takeover or content loss may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Botiga Pro WordPress plugin's lack of authorization checks on its REST routes presents a critical risk, enabling unauthenticated users to escalate privileges, execute arbitrary scripts, and manipulate content. This issue demands immediate attention from teams managing WordPress instances, specifically application owners or platform teams responsible for plugin management and website security. The first practical step involves identifying all deployed instances of the plugin, assessing their exposure, and confirming business criticality to prioritize remediation efforts.

  • WordPress application owners.
  • Verify plugin presence and reachability.
  • Coordinate vendor updates or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Botiga Pro WordPress plugin?

Botiga Pro is a premium plugin used to enhance the functionality and design of WordPress websites, often providing features like advanced styling, custom widgets, and e-commerce integrations. It operates within the WordPress ecosystem to help site administrators manage their front-end appearance and content structure.

How does CVE-2026-86591 work?

This vulnerability is classified as CWE-862, which is a Missing Authorization flaw. Essentially, the plugin fails to check if a person visiting a specific part of the site is allowed to perform administrative tasks. Because these security checks are absent, an unauthorized user can interact with internal site settings as if they were a trusted administrator.

What triggers this vulnerability?

The flaw is triggered when someone sends a network request to specific REST routes provided by the plugin. Simply browsing the site or viewing public pages does not trigger the bug; it requires an intentional, direct interaction with these unprotected programming interfaces. If the plugin's REST endpoints are accessed directly, the unauthorized actions proceed without any authentication requirements.

Do I need to worry about this if my site is internal?

According to Halo Surface Signal, this vulnerability is considered a high-priority risk because WordPress sites are typically designed as public-facing services. While internal sites may have a smaller attack surface, the REST routes are accessible over the network to anyone who can reach the site. If your instance is reachable from the internet, it is highly likely that these unprotected routes are also exposed.

What should I do to address CVE-2026-86591?

Your first step is to perform an inventory of your WordPress environments to identify where the Botiga Pro plugin is currently installed. Once you have located all instances, evaluate which sites are accessible from the internet and prioritize them for action. Coordinate with your team to review available vendor updates or, if an update is not immediately feasible, consider temporarily disabling the plugin to mitigate the risk of unauthorized access.

References