WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
Title source: cnaExploitation Summary
CVE-2026-49060 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including rootdirective-sec.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2026-49060, targeting an authentication bypass vulnerability in the Hippoo plugin for WordPress. The PoC includes a Python script to validate the vulnerability by probing REST endpoints and attempting unauthenticated password updates.
Description
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
Exploits (1)
This repository contains a functional exploit PoC for CVE-2026-49060, targeting an authentication bypass vulnerability in the Hippoo plugin for WordPress. The PoC includes a Python script to validate the vulnerability by probing REST endpoints and attempting unauthenticated password updates.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H