Authorization Bypass in OpenStation Plugin for WordPress by OpenStation
CVE-2026-19775
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-19775?
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress allows authenticated users to bypass authorization checks. This vulnerability arises from inadequate verification of user permissions, enabling attackers with custom-level access to view sensitive information such as private posts and unapproved comments. Users can exploit this weakness by enabling specific AI features via the plugin interface, thus gaining further access to restricted content within the WordPress environment.
Affected Version(s)
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin 0 <= 1.1.7