---
id: CVE-2026-86785
title: >-
  The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not
  have authorisation checks on some of its REST API endpoints, allowing
  unauthenticated users to update Social Commerce for WooCommerce WordPress
  plugin through 2.…
summary: >-
  The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not
  have authorisation checks on some of its REST API endpoints, allowing
  unauthenticated users to update Social Commerce for WooCommerce WordPress
  plugin through 2.…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Social Commerce for WooCommerce
affected:
  - social_commerce_for_woocommerce <= 2.5.4
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:12:32.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86785'
references:
  - url: 'https://wpscan.com/vulnerability/9a4c36bd-c7f7-4068-ac73-b29ee66def96/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00182
epssPercentile: 0.06838
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T10:43:41.027335Z'
ingestedAt: '2026-09-23T06:17:57.895Z'
---

## Overview

The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
