CVE-2026-32586

WordPress Booster for WooCommerce plugin < 7.11.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through < 7.11.3.


We have discovered 1,360 live websites that are affected by CVE-2026-32586.

Run a Free Instant Scan




Affected Software

Product  Woocommerce Jetpack
Category Wordpress Plugins
Vulnerable Domains1,360 live websites (100% of Woocommerce Jetpack install base)
Vulnerable Versions
  • from 0 through 7.11.3
Vulnerable Versions Count76 versions ( 100% of all versions)



Details

  • Published - Mar 17, 2026
  • Updated - Apr 1, 2026

Credits

  • Nguyen Ba Khanh | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32586
United States421 websites



Italy94 websites
GB92 websites
Germany83 websites
France66 websites
Netherlands66 websites
Spain37 websites
Australia35 websites
Poland31 websites
South Africa30 websites

Website Distribution by TLD

Number of websites using CVE-2026-32586
.com568 websites
.it69 websites
.co.uk68 websites
.nl53 websites
.org49 websites
.de34 websites
.com.au32 websites
.net32 websites
.fr26 websites
.es24 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32586

Top websites that are affected by CVE-2026-32586. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
************.***.uk GB***,***
**********************.at Germany***,***
************.com United States***,***
*****.de Germany***,***
******.org France***,***
****.org United States***,***
******************.com United States***,***
******.org United States***,***
***************.org Germany***,***
See full domain list

FAQ

A total of 1,360 websites have been identified as vulnerable to CVE-2026-32586, based on global website indexing conducted by WebTechSurvey.
The Woocommerce Jetpack is affected by the CVE-2026-32586 vulnerability.
Woocommerce Jetpack versions up to and including 7.11.3 are vulnerable to CVE-2026-32586.