---
id: CVE-2026-9766
title: >-
  The Empik for Woocommerce plugin for WordPress is vulnerable to authorization
  bypass in all versions up to, and including, 1.5.1
summary: >-
  The Empik for Woocommerce plugin for WordPress is vulnerable to authorization
  bypass in all versions up to, and including, 1.5.1. This is due to the plugin
  not properly verifying that a user is authorized to perform an action. This
  makes…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: empik
product: Empik for Woocommerce
affected:
  - for_woocommerce <= 1.5.1
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9766'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/CSV/CSV_Ajax.php#L12
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/CSV/CSV_Ajax.php#L19
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/CSV/CSV_Ajax.php#L64
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/CSV/CSV_Import.php#L38
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/Products_List_Offers_import_Column.php#L29
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/empik-for-woocommerce/tags/1.5.1/src/Wp_Admin/Products_List_Product_import_Column.php#L28
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3592900%40empik-for-woocommerce&new=3592900%40empik-for-woocommerce
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/a0a5259d-7340-48b5-a0cf-f68abdb21156?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00232
epssPercentile: 0.14369
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:17:25.326650Z'
ingestedAt: '2026-09-19T09:00:39.470Z'
---

## Overview

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary WooCommerce product metadata, including Empik logistic class (_empik_logistic_klass), product state (_empik_product_state, _empik_product_state_all_variants), and Empik export and offer flags on any product in the store.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
