Unauthorized Data Modification in Builderall Cheetah Plugin for WordPress
CVE-2026-15823
4.3MEDIUM
What is CVE-2026-15823?
The Builderall Cheetah for WordPress plugin suffers from a vulnerability that allows authenticated users with Subscriber-level access or higher to modify post layouts maliciously. This weakness arises from a lack of proper capability and nonce checks in the AJAX wp_ajax_ba_cheetah_disable handler, enabling attackers to manipulate the post metadata by directly submitting the post_id via user-controlled input. As a result, they can disable the page builder layout on any post, including those created by other users, potentially disrupting website functionality and integrity.
Affected Version(s)
Builderall for WordPress 0 <= 3.0.2