CVE-2026-88828: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Blacklist Manager
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
AI Analysis
Technical Summary
The Blacklist Manager plugin for WooCommerce WordPress versions >=1.3.0 and <2.3.2 contains an authentication bypass vulnerability (CWE-288). The plugin fails to enforce user blocking on every authentication path, enabling blocked users to authenticate and retain their privileges despite being blocked by the site owner. This flaw allows unauthorized access continuation without detection.
Potential Impact
A user who has been blocked by the site owner can still authenticate and access the site with their account privileges. This bypass undermines the intended access control and user blocking mechanisms, potentially allowing unauthorized actions with limited confidentiality and integrity impact. There is no indication of availability impact or active exploitation in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider additional manual controls or monitoring to detect unauthorized access by blocked users.
CVE-2026-88828: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Blacklist Manager
Description
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
CVSS v3.1
Score 5.4medium
Affected software
Blacklist Manager
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Blacklist Manager plugin for WooCommerce WordPress versions >=1.3.0 and <2.3.2 contains an authentication bypass vulnerability (CWE-288). The plugin fails to enforce user blocking on every authentication path, enabling blocked users to authenticate and retain their privileges despite being blocked by the site owner. This flaw allows unauthorized access continuation without detection.
Potential Impact
A user who has been blocked by the site owner can still authenticate and access the site with their account privileges. This bypass undermines the intended access control and user blocking mechanisms, potentially allowing unauthorized actions with limited confidentiality and integrity impact. There is no indication of availability impact or active exploitation in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider additional manual controls or monitoring to detect unauthorized access by blocked users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-10T09:34:02.869Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba0dbef7a7c541064c334f
Added to database: 09/28/2026, 06:48:30 UTC
Last enriched: 09/28/2026, 07:03:16 UTC
Last updated: 09/29/2026, 01:57:22 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.