CVE-2026-49065 is a high-severity vulnerability (CVSS Score: 8.2) affecting the Hippoo Mobile App for WooCommerce plugin versions <= 1.9.5. This vulnerability is classified as Unauthenticated Broken Access Control. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-49065) and additional details can be found on [nvd](https://nvd.nist.gov/vuln/detail/CVE-2026-49065).
CVE-2026-10580 is a critical vulnerability in the Hippoo Mobile App for WooCommerce plugin for WordPress. The plugin is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This issue arises from a logic conflation in `HippooPermissions::get_user_permissions()`, which returns the same null sentinel for both administrators and unauthentica [truncated]