All verified exploits

CVE-2026-2631 Datalogics Plugin Privilege Escalation

Deterministic critical WordPress Added cve-verified-cve-2026-2631

Detects the Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60, where an unauthenticated REST API endpoint allows arbitrary WordPress option updates. Attackers can enable user registration and set the default role to Administrator, gaining full control of the install.

Related WordPress exploits

Is your app exploitable through CVE-2026-2631?

Scan your domain free