Authorization Bypass in Flamingo Plugin for WordPress
CVE-2026-12853

5.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-12853?

The Flamingo plugin for WordPress contains a significant flaw that allows authenticated users with contributor-level access and above to bypass authorization controls. This vulnerability permits attackers to enumerate taxonomy terms related to internal forms, department names, workflow identifiers, and submission counts. The plugin fails to adequately validate a user's permissions when accessing certain functionalities, especially through key WordPress core APIs like XML-RPC and admin-ajax. This oversight could lead to potential exposure of sensitive data, undermining the security of the application and its operations.

Affected Version(s)

Flamingo 0 <= 2.6.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jopet
.