CVE-2026-10580 is a critical authentication bypass vulnerability in the Hippoo Mobile App for WooCommerce plugin for WordPress affecting all versions up to and including 1.9.4. The flaw is caused by improper authorization logic in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both authenticated administrators and unauthenticated visitors. HippooPermissions::has_role_access() then incorrectly interprets that null value as full administrator access. As a result, override_extension_permission_callback() assigns permissive access to cloned WordPress and WooCommerce REST routes re-registered by HippooControllerWithAuth::re_register_external_routes(), and block_unauthorized_access() fails to stop unauthenticated requests for the same reason. This exposes cloned core REST functionality to anonymous users and allows unauthorized actions such as resetting arbitrary user passwords, including the administrator account, resulting in full site compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a small exploit package for CVE-2026-10580 targeting the WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4. There are 5 files total: one standalone Python exploit, one Nuclei template, a README, license, and .gitignore. Because the repository includes a Nuclei template, it can be considered framework-associated; however, the repo also ships a direct Python PoC. Main exploit capability: unauthenticated account takeover by abusing a vulnerable REST API route. The Python script first enumerates users from /wp-json/wc-hippoo/v1/ext/wp/v2/users, extracting IDs, usernames, and roles. It then sends a POST request with JSON body containing a new password to /wp-json/wc-hippoo/v1/ext/wp/v2/users/{id}, allowing arbitrary password reset without authentication. On success it prints the wp-admin login URL and recovered admin username if found. This is a real exploit, not merely a detector. The Nuclei template performs a two-step workflow: first checks /wp-content/plugins/hippoo/readme.txt to confirm plugin presence/version, then attempts password reset against /wp-json/wc-hippoo/v1/ext/wp/v2/users/1 using a generated password. Matchers look for HTTP 200 and WordPress user metadata in the response, making it an intrusive exploitation template rather than passive detection. Overall purpose: provide both automated scanning/exploitation via Nuclei and an operator-friendly Python PoC for manual exploitation of vulnerable WordPress sites. The exploit is high impact because it enables full administrator takeover with no prior credentials.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
An authentication bypass vulnerability in the Hippoo Mobile App for WooCommerce WordPress plugin that can lead to administrator account takeover by allowing unauthenticated access to cloned WordPress and WooCommerce REST endpoints.
A critical authentication bypass / improper authorization flaw in the Hippoo Mobile App for WooCommerce WordPress plugin that allows unauthenticated attackers to gain administrator-level access via cloned REST API routes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.