---
id: CVE-2026-86850
title: >-
  The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not
  perform any capability or nonce checks on two of its AJAX actions, which are
  also available to unauthenticated users, allowing them to permanently delete
  product v…
summary: >-
  The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not
  perform any capability or nonce checks on two of its AJAX actions, which are
  also available to unauthenticated users, allowing them to permanently delete
  product v…
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T07:17:18.750'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86850'
references:
  - url: 'https://wpscan.com/vulnerability/889aaa2a-ad05-423a-a601-70ac1d8b7920/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-09T07:28:22.266Z'
---

## Overview

The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
