CVE-2026-2001 describes a critical vulnerability in the WowRevenue WordPress plugin, affecting all versions up to and including 2.1.3. This flaw allows authenticated attackers with subscriber-level privileges to install arbitrary plugins due to a missing capability check, potentially leading to remote code execution. The vulnerability carries a high CVSS score of 8.8, indicating a severe risk with low attack complexity and high impact on confidentiality, integrity, and availability. While there is currently no evidence of active exploitation, nor publicly available exploit code in Metasploit or Nuclei, its high FAUCET Risk Score of 94/100 warrants immediate attention. Community discussion and media coverage are minimal, which is typical for many CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wpxpo | WowRevenue – Product Bundles & Bulk Discounts | >= 0, <= 2.1.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.