CVE-2026-10580 | Hippoo Mobile App for WooCommerce Plugin up to 1.9.4 on WordPress REST Endpoint /wc-hippoo/v1/ext get_user_permissions improper authorization

SecurityVulns

A vulnerability labeled as critical has been found in Hippoo Mobile App for WooCommerce Plugin up to 1.9.4 on WordPress. Affected is the function HippooPermissions::get_user_permissions of the file /wc-hippoo/v1/ext of the component REST Endpoint. The manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2026-10580. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More