CVE-2026-11446 | Booktics Plugin up to 1.0.23 on WordPress Permission Callback orders create_order_permission privileges management
A vulnerability described as problematic has been identified in Booktics Plugin up to 1.0.23 on WordPress. Impacted is the function create_order_permission of the file /wp-json/booktics/v1/orders of the component Permission Callback. The manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-11446. It is possible to launch the attack remotely. No exploit is available.