A vulnerability, which was classified as critical , was found in Webkul Bagisto up to 2.4.4 . Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint . Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2026-19835 . The attack can be launched remotely. Moreover, an exploit is present. The vendor confirms: "The reported issues were already identified through our internal security assessment proc