CVE-2026-1128: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1128 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP eCommerce WordPress plugin that allows unauthenticated attackers to trick a logged-in administrator into deleting store coupons. It affects all versions of the plugin through 3.15.1, with no known fix available at the time of disclosure. The vulnerability was publicly disclosed on February 13, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (WPScan, Red Hat CVE).

Technical details

The root cause is a missing CSRF token validation (CWE-352) on the coupon deletion endpoint in the WP eCommerce plugin's admin interface. An attacker can craft a malicious URL or hidden HTML form targeting the wp-admin/edit.php endpoint with the action=delete parameter and specific coupon IDs, then socially engineer an authenticated administrator into visiting or loading that URL. No authentication is required on the attacker's side — only the victim must be logged in as an admin. A proof-of-concept URL is publicly documented: https://example.com/wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[0]=4&coupon[1]=5 (WPScan).

Impact

Successful exploitation allows an attacker to permanently delete discount coupons from a WP eCommerce store without the administrator's knowledge or consent, impacting the integrity of the store's promotional configuration. There is no confidentiality or availability impact — the attack is limited to unauthorized data modification (coupon deletion). While not directly enabling lateral movement or data exfiltration, repeated exploitation could disrupt e-commerce operations by removing valid promotional codes (WPScan).

Exploitability

A public proof-of-concept URL is documented in the WPScan advisory, making exploitation straightforward for any attacker who can deliver a crafted link to a logged-in administrator. The EPSS score is very low at 0.000080, indicating minimal observed exploitation activity, and there is no evidence of in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (WPScan, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP eCommerce plugin (version ≤ 3.15.1) using tools like WPScan or by inspecting page source for plugin indicators.
  2. Enumerate coupon IDs: If the attacker has any read access or can infer coupon IDs through store behavior, identify valid coupon post IDs in the WordPress database (typically sequential integers).
  3. Craft malicious URL: Construct a URL targeting the vulnerable endpoint, e.g., https://victim-site.com/wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[0]=4&coupon[1]=5, substituting real coupon IDs.
  4. Deliver to administrator: Send the crafted URL to a logged-in administrator via phishing email, forum post, or embedded in an image/iframe on a page the admin is likely to visit.
  5. Coupon deletion triggered: When the administrator's browser loads the URL while authenticated, the server processes the deletion request without verifying a CSRF token, permanently removing the specified coupons (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing GET requests to /wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[]=... from unexpected referrers or external IP addresses.
  • Application Events: Unexpected coupon deletion events in the WP eCommerce admin activity log or WordPress audit log plugins, particularly outside of normal business hours or from admin accounts that did not initiate the action.
  • Network: HTTP requests to the coupon deletion endpoint originating from an admin session but with a Referer header pointing to an external or unexpected domain.

Mitigation and workarounds

As of the disclosure date (February 13, 2026), there is no known fix available for the WP eCommerce plugin through version 3.15.1 (WPScan). Site administrators should monitor the plugin's repository for a patched release and update immediately when one becomes available. In the interim, consider disabling the plugin if coupon functionality is not critical, restricting admin account access, and training administrators to avoid clicking unsolicited links while logged into the WordPress dashboard.

Community reactions

The vulnerability was discovered and reported by independent researcher Bob Matyas, who also submitted it to WPScan. No significant vendor statements, major media coverage, or notable community discussion beyond the WPScan advisory have been identified for this moderate-severity issue (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management