{"id":"CVE-2026-92404","title":"The MgoSync  WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and …","summary":"The MgoSync  WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"product":"MgoSync","affected":["MgoSync >= 2.1.5 < 2.1.7"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:34:57.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92404","references":[{"url":"https://wpscan.com/vulnerability/342e79ec-cfe6-43f3-8598-bf2b83aff2a1/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00256,"epssPercentile":0.17538,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-19T13:11:11.754576Z"},"ingestedAt":"2026-09-19T06:59:13.117Z","slug":"CVE-2026-92404","body":"## Overview\n\nThe MgoSync  WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":207712,"id":"CVE-2026-92404","ts":1789826664399,"field":"cvss","old":null,"new":"7.5"},{"seq":207711,"id":"CVE-2026-92404","ts":1789826664399,"field":"severity","old":"none","new":"high"}]}