← back
CVE-2026-92404highCWE-200

MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.5epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Unknown · MgoSync
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.