CVE-2026-92404 PUBLISHED

MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure

Assigner: WPScan
Reserved: 16.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.

Product Status

Vendor Unknown
Product MgoSync
Versions Default: unaffected
  • affected from 2.1.5 to 2.1.7 (excl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente finder
  • and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE