CVE WATCH / VULNERABILITY DETAIL
CVE-2026-86850
MEDIUMCVSS 6.5NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those vari
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8
- CVE-2026-94065 HIGH 8.8
- CVE-2026-100730 CRITICAL 9.8
- CVE-2026-94062 HIGH 8.1
- CVE-2026-62028 MEDIUM 5.4