CVE-2026-3460Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing WordPress user, while the callback function (update_user_wechatshop_info) uses a separate, attacker-controlled 'userid' parameter to determine which user's metadata gets modified, with no verification that the 'openid' and 'userid' belong to the same user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary users' store-related metadata (storeinfo, storeappid, storename) via the 'userid' REST API parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-21: 2Technical Details · 2026-03-21: 203-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3460 WordPress REST API TO MiniProgram Plugin Insecure Direct Object Reference Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3460

    Post summary

    A new insecure direct object reference vulnerability (CVE-2026-3460) affecting the WordPress REST API to MiniProgram Plugin has been disclosed, with no PoC, exploit, or patch details provided.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3460 The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permi… https://www.cve.org/CVERecord?id=CVE-2026-3460

    Post summary

    The CVE‑2026‑3460 entry reveals an Insecure Direct Object Reference vulnerability affecting all WordPress REST API TO MiniProgram plugin versions up to 5.1.2, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000070
    56.8K followersView on X

Explore more