CVE-2026-2631Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-23); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-15: 1Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-21: 1PoC Mentioned / Linked · 2026-03-23: 2Exploit Tool / Code · 2026-03-21: 1Exploit Tool / Code · 2026-03-23: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-26: 103-1103-1503-2103-2303-26
Signal classification4 categories
Disclosure
233.3%
PoC
233.3%
Exploit
116.7%
Patch
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-151
Disclosure1
2026-03-211
PoC1
2026-03-232
Exploit1PoC1
2026-03-261
Patch1
Full discourse6 posts
  • Nxploited@Nxploited
    Exploit

    CVE-2026-2631 – Datalogics Ecommerce Delivery (WordPress) – Unauthenticated Privilege Escalation PoC: https://github.com/Nxploited/CVE-2026-2631 PoC / Exploit Script: Author: Khaled Alenazi (Nxploited) – Nxploited ZeroDay HubContact: Telegram: @Kxploit #hacker #cyberattack #Exploit #CVE

    Post summary

    The tweet announces CVE‑2026‑2631 and shares a PoC/exploit script on GitHub, confirming vulnerability details but no evidence of active exploitation or patch status.

    00012204
    94 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-2631 is a serious #WordPress risk in Datalogics Ecommerce Delivery < 2.6.60. https://nvd.nist.gov/vuln/detail/CVE-2026-2631 What’s the risk: unauthenticated attackers may change site options, enable registration, set the default role to Administrator, and take over the website. How to protect your site: update immediately. #WordPressSecurity #CVE #WebsiteSecurity #malware #cybersecurity #infosec #riskmanagement #dataprotection #digitaltrust #compliance #cyberattack #securityleadership

    Post summary

    CVE-2026-2631 enables unauthenticated attackers to take over WordPress sites by altering site options and default roles; immediate update is recommended to mitigate the risk.

    0000034
    38 followersView on X
  • dbugs@ptdbugs
    PoC

    Datalogics Ecommerce Delivery WordPress Plugin < 2.6.60 - Unauthenticated Privilege Escalation CVE: CVE-2026-2631 PT-Identifier: PT-2026-24588 Vendor: WordPress Product: Datalogics Ecommerce Delivery CVSS: 9.8 Credits: Khaled Alenazi (Nxploited) Description: The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option "datalogics_token" without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress "update_option()" operations. Attackers can use this to enable registartion and to set the default role as Administrator. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-2631 • https://wpscan.com/vulnerability/c6a64f26-4007-49a1-aa69-1e3c50223ac7/ Exploit: https://github.com/Nxploited/CVE-2026-2631 #dbugs_vuln

    Post summary

    The post discloses a critical privilege escalation flaw in Datalogics Ecommerce Delivery <2.6.60, provides technical details and a CVSS score, and shares a proof‑of‑concept exploit on GitHub, but does not mention active exploitation or patch information.

    0000079
    733 followersView on X
  • Brinztech@Brinztech_com
    PoC

    Brinztech Alert: Public PoC Shared for CVE-2026-2631 (Datalogics Ecommerce Delivery) https://www.brinztech.com/breach-alerts/brinztech-alert-public-poc-shared-for-cve-2026-2631-datalogics-ecommerce-delivery/

    Post summary

    A public proof‑of‑concept for CVE-2026-2631 affecting Datalogics Ecommerce Delivery has been released, with a link to the shared PoC.

    0000082
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2631 The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_… https://www.cve.org/CVERecord?id=CVE-2026-2631

    Post summary

    The Datalogics Ecommerce Delivery WordPress plugin prior to 2.6.60 is vulnerable to unauthenticated REST endpoint exploitation that permits remote modification of plugin options.

    00000161
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2631 - Critical The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verif... https://www.thehackerwire.com/vulnerability/CVE-2026-2631/ https://t.co/tfjRjzcQQo

    Post summary

    The text announces a critical vulnerability (CVE-2026-2631) in the Datalogics Ecommerce Delivery WordPress plugin, detailing an unauthenticated REST endpoint that permits remote modification of the `datalogics_token` option.

    0000040
    134 followersView on X

Explore more