Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #10
Kit patches missing authorization flaw in WooCommerce plugin
Original: CVE-2026-105421: Kit has patched a missing authorization vulnerability in its Kit (formerly ConvertKit) for WooCommerce
Kit, the email marketing service formerly known as ConvertKit, has patched a missing authorization vulnerability tracked as CVE-2026-105421 in its Kit for WooCommerce WordPress plugin. Versions through 2.2.0 are affected, and the fix is available in version 2.2.1. No exploitation in the wild has been confirmed, but security researchers are urging users of the plugin to update promptly.
Why now: A newly assigned CVE in a widely used WooCommerce plugin prompts admins to check whether they need to update.
KitConvertKitWooCommerceCVE-2026-105421
Evidence
- CVE-2026-105421: Kit has patched a missing authorization vulnerability in its Kit (formerly ConvertKit) for WooCommerce plugin. Versions through 2.2.0 are affected. No exploitation in the wild is confirmed. The fix is available in version 2.2.1. https://www.… · suriq@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1129374