External risk intelligence

WordPress wpShopGermany Plugin Remote Code Execution Via Insecure API Token Generation.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-88795

The vulnerability affects a WordPress plugin, which is a component of a web application. WordPress sites and their associated plugins are commonly deployed as internet-facing services, making the attack surface accessible via public web requests.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability concerns a WordPress plugin that generates API authentication tokens insecurely. Attackers could potentially predict these tokens to gain unauthorized access and execute arbitrary code on affected systems. The main concern is confirming the relevance and exposure of this plugin within your digital environment.

  • Insecure tokens allow code execution.
  • Critical flaw affects a widely used platform.
  • Confirm exposure and plugin relevance.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could target the wpShopGermany IT-RECHT KANZLEI WordPress plugin by predicting a poorly generated API authentication token. This token, created as a side effect of a validation check, grants access to write arbitrary files. Successful exploitation allows for remote code execution on the affected site.

  • No authentication is required.
  • Predictable API token generation.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow unauthenticated attackers to predict an API authentication token. This predicted token may then be used to write arbitrary files to the system, potentially leading to remote code execution under specific conditions where the plugin generates tokens insecurely.

  • Arbitrary file writes to the system.
  • Predictable API token generation.
  • Remote code execution may be possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The wpShopGermany IT-RECHT KANZLEI WordPress plugin's insecure API token generation presents a critical risk, enabling unauthenticated remote code execution. Technical leaders and security teams must first identify all instances of this plugin, determine their internet-facing status and business criticality, and then assign ownership to the appropriate team for remediation planning.

  • WordPress site owners should own the issue.
  • Verify external reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the wpShopGermany IT-RECHT KANZLEI plugin?

This is a specialized extension for WordPress designed to help online store owners meet German legal requirements for e-commerce. It manages essential features like automated legal texts, terms and conditions, and imprint generators, which are critical for site compliance within that region.

What does CWE-94 mean for CVE-2026-88795?

CWE-94 refers to improper control of generation of code. In this vulnerability, the flaw allows an attacker to influence or predict the API authentication token used by the plugin. Because the plugin uses this insecure process to validate requests, an attacker can bypass access controls to inject and execute arbitrary code on the server.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending crafted web requests to the plugin's API. Because the plugin creates the authentication token as a side effect during its validation check—using data the requester controls—an attacker can predict the valid token. Note that simply having the plugin installed does not trigger the bug unless the specific insecure API endpoint is reachable and processed by the system.

Is my site at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is classified as external because WordPress plugins typically operate as internet-facing services. If your site uses this plugin and is accessible over the public web, your system is likely within the attack surface for this threat.

Do I need to take action if I use this plugin?

Yes. First, audit your WordPress installations to locate any instances of the wpShopGermany IT-RECHT KANZLEI plugin. Once identified, evaluate if the site is internet-facing and determine its business criticality. Prioritize updating the plugin to version 2.4 or higher to resolve the insecure token generation flaw.

References