CVE-2026-88828 Details
Description
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
A vulnerability exists in the Blacklist Manager for WooCommerce WordPress plugin, versions 1.3.0 to 2.3.1. The plugin fails to consistently enforce user blocking across all authentication methods. This oversight allows users with blocked accounts to continue accessing the site with their account privileges, without the block being applied or logged.
Users are advised to update the Blacklist Manager for WooCommerce WordPress plugin to version 2.3.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/52804421-8988-4d8a-9143-04683d05873d/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Blacklist Manager | >= 1.3.0, <= 2.3.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion