MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #10

Kit patches missing authorization flaw in WooCommerce plugin

Original: CVE-2026-105421: Kit has patched a missing authorization vulnerability in its Kit (formerly ConvertKit) for WooCommerce

Kit, the email marketing service formerly known as ConvertKit, has patched a missing authorization vulnerability tracked as CVE-2026-105421 in its Kit for WooCommerce WordPress plugin. Versions through 2.2.0 are affected, and the fix is available in version 2.2.1. No exploitation in the wild has been confirmed, but security researchers are urging users of the plugin to update promptly.

Why now: A newly assigned CVE in a widely used WooCommerce plugin prompts admins to check whether they need to update.

KitConvertKitWooCommerceCVE-2026-105421

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1129374