Ibtana Ecommerce Addons WP v0.4.7.7: Unauthorized Post Meta via AJAX
CVE-2026-1984 Published on September 19, 2026
Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action
The Ibtana Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.
Timeline
Disclosed
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-1984 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
vowelweb Ibtana – Ecommerce Product Addons:- Before and including 0.4.7.7 is affected.