Detects the Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60, where an unauthenticated REST API endpoint allows arbitrary WordPress option updates. Attackers can enable user registration and set the default role to Administrator, gaining full control of the install.
Is your app exploitable through CVE-2026-2631?
Scan your domain free