Ibtana Ecommerce Addons WP v0.4.7.7: Unauthorized Post Meta via AJAX
CVE-2026-1984 Published on September 19, 2026

Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action
The Ibtana Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.

NVD

Timeline

Disclosed

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-1984 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

vowelweb Ibtana – Ecommerce Product Addons: