
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3460 is an Insecure Direct Object Reference (IDOR) vulnerability in the REST API TO MiniProgram plugin for WordPress, affecting all versions up to and including 5.1.2. The flaw allows authenticated attackers with Subscriber-level access or above to modify arbitrary users' store-related metadata by supplying an attacker-controlled userid parameter that is not validated against the authenticated user's identity. It was published on March 21, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence).
The root cause is an authorization bypass through a user-controlled key (CWE-639 / CWE-20: Improper Input Validation). The permission callback update_user_wechatshop_info_permissions_check only verifies that the supplied openid parameter corresponds to an existing WordPress user, but the actual data-modification callback update_user_wechatshop_info uses a separate userid parameter — fully controlled by the attacker — to determine which user's metadata is updated. Because no cross-validation is performed to confirm that openid and userid belong to the same account, any authenticated subscriber can target any other user's record. The vulnerable code is located in includes/api/ram-rest-weixin-controller.php at lines 216, 309, and 924 (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to overwrite the storeinfo, storeappid, and storename metadata fields of any WordPress user registered on the site, including administrators and shop owners. While confidentiality and availability are not directly impacted, the integrity impact could disrupt e-commerce or WeChat Mini Program integrations by corrupting store configurations, potentially redirecting transactions or disrupting business operations. The scope is limited to the affected WordPress installation, with no direct path to remote code execution or lateral movement based on currently known information (Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-3460 as of the available data. The vulnerability requires at minimum a Subscriber-level WordPress account, limiting opportunistic exploitation. The EPSS score is approximately 0.039% (0.000390), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
/wp-json/wp/v2/users) to find the numeric userid of the victim account.openid: Supply any valid openid value that corresponds to an existing WordPress user (not necessarily the victim) to pass the permission check.POST /wp-json/<plugin-route>/update_user_wechatshop_info) with the valid openid and the victim's userid, along with arbitrary values for storeinfo, storeappid, and storename.update_user_wechatshop_info endpoint where the userid parameter does not match the authenticated user's own ID; repeated requests from the same IP targeting multiple different userid values.openid and userid parameters; multiple rapid requests from a single subscriber account modifying different user records.usermeta entries for storeinfo, storeappid, or storename fields, particularly for high-privilege accounts such as administrators or shop owners.Users should update the REST API TO MiniProgram plugin to version 5.1.3 or later, which addresses the IDOR vulnerability by enforcing proper cross-validation between the openid and userid parameters. As a temporary workaround, site administrators can restrict REST API access to authenticated users only or disable the plugin until patching is feasible. Limiting user registration and subscriber-level account creation on the site will also reduce the attack surface (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."