CVE-2026-3460: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3460 is an Insecure Direct Object Reference (IDOR) vulnerability in the REST API TO MiniProgram plugin for WordPress, affecting all versions up to and including 5.1.2. The flaw allows authenticated attackers with Subscriber-level access or above to modify arbitrary users' store-related metadata by supplying an attacker-controlled userid parameter that is not validated against the authenticated user's identity. It was published on March 21, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence).

Technical details

The root cause is an authorization bypass through a user-controlled key (CWE-639 / CWE-20: Improper Input Validation). The permission callback update_user_wechatshop_info_permissions_check only verifies that the supplied openid parameter corresponds to an existing WordPress user, but the actual data-modification callback update_user_wechatshop_info uses a separate userid parameter — fully controlled by the attacker — to determine which user's metadata is updated. Because no cross-validation is performed to confirm that openid and userid belong to the same account, any authenticated subscriber can target any other user's record. The vulnerable code is located in includes/api/ram-rest-weixin-controller.php at lines 216, 309, and 924 (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker to overwrite the storeinfo, storeappid, and storename metadata fields of any WordPress user registered on the site, including administrators and shop owners. While confidentiality and availability are not directly impacted, the integrity impact could disrupt e-commerce or WeChat Mini Program integrations by corrupting store configurations, potentially redirecting transactions or disrupting business operations. The scope is limited to the affected WordPress installation, with no direct path to remote code execution or lateral movement based on currently known information (Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-3460 as of the available data. The vulnerability requires at minimum a Subscriber-level WordPress account, limiting opportunistic exploitation. The EPSS score is approximately 0.039% (0.000390), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Obtain Subscriber-level access: Register or log in to the target WordPress site with any account that has at least Subscriber privileges.
  2. Identify a target user: Enumerate WordPress user IDs (e.g., via the WordPress REST API /wp-json/wp/v2/users) to find the numeric userid of the victim account.
  3. Obtain a valid openid: Supply any valid openid value that corresponds to an existing WordPress user (not necessarily the victim) to pass the permission check.
  4. Craft a malicious REST API request: Send an authenticated HTTP request to the plugin's REST API endpoint (e.g., POST /wp-json/<plugin-route>/update_user_wechatshop_info) with the valid openid and the victim's userid, along with arbitrary values for storeinfo, storeappid, and storename.
  5. Confirm metadata modification: Verify that the target user's store metadata has been overwritten by querying the affected user's profile or observing changes in the Mini Program storefront (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected REST API POST requests to the plugin's update_user_wechatshop_info endpoint where the userid parameter does not match the authenticated user's own ID; repeated requests from the same IP targeting multiple different userid values.
  • Logs: WordPress access logs showing authenticated REST API calls to the plugin endpoint with mismatched openid and userid parameters; multiple rapid requests from a single subscriber account modifying different user records.
  • Database: Unexpected or unauthorized changes to WordPress usermeta entries for storeinfo, storeappid, or storename fields, particularly for high-privilege accounts such as administrators or shop owners.

Mitigation and workarounds

Users should update the REST API TO MiniProgram plugin to version 5.1.3 or later, which addresses the IDOR vulnerability by enforcing proper cross-validation between the openid and userid parameters. As a temporary workaround, site administrators can restrict REST API access to authenticated users only or disable the plugin until patching is feasible. Limiting user registration and subscriber-level account creation on the site will also reduce the attack surface (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93549HIGH8.8
  • cart-rest-api-for-woocommerce
NoYesOct 04, 2026
CVE-2026-78371MEDIUM5.9
  • woo-addon-uploads
NoYesOct 05, 2026
CVE-2026-13607MEDIUM5.9
  • woo-addon-uploads
NoNoOct 05, 2026
CVE-2026-84169MEDIUM5.3
  • upi-qr-code-payment-gateway
NoNoOct 05, 2026
CVE-2026-97332MEDIUM5.3
  • user-private-files
NoYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management