CVE-2026-39701 | Andrew ShopWP Plugin up to 5.2.4 on WordPress authorization
A vulnerability classified as critical was found in Andrew ShopWP Plugin up to 5.2.4 on WordPress. This affects an unknown part. The manipulation results in missing authorization.
This vulnerability is known as CVE-2026-39701. It is possible to launch the attack remotely. No exploit is available.