{"id":"CVE-2026-92404","published":"2026-09-19T07:16:33.790","lastModified":"2026-09-21T13:34:57.127","description":"The MgoSync  WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/342e79ec-cfe6-43f3-8598-bf2b83aff2a1/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}