MEDIUM
CP Image Store with Slideshow <= 1.1.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import
Published Jan 13, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.29%
Description
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import arbitrary products via XML, if the XML file has already been uploaded to the server.
Affected products
-
- Version 0StatusaffectedConstraints<=1.1.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Codepeople | CP Image Store with Slideshow | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2352 Advisory
- https://plugins.trac.wordpress.org/browser/cp-image-store/tags/1.1.9/cp-image-store.php#L826
- https://plugins.trac.wordpress.org/changeset/3434716/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/28e48604-2aaf-4e02-9b1e-cebf5f0bfcf7?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jan 13, 2026
Updated Apr 8, 2026
Reserved Jan 7, 2026
Link CVE-2026-0684
CISA Vulnrichment
Updated Jan 13, 2026
ENISA EUVD
EUVD-2026-2352 Assigner Wordfence
Published Jan 13, 2026
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2026-2352