Unauthorized Data Modification in Emailchef Plugin for WordPress
CVE-2026-1930
4.3MEDIUM
What is CVE-2026-1930?
The Emailchef plugin for WordPress contains a vulnerability that allows authenticated users with Subscriber-level access and above to modify data without appropriate capability checks. Specifically, the flaw exists in the page_options_ajax_disconnect() function. This weakness enables such users to delete the plugin's settings through the 'emailchef_disconnect' AJAX action, posing potential risks to the integrity and functionality of the user's WordPress installation.
Affected Version(s)
Emailchef 0 <= 3.5.1