Authorization Bypass in OpenStation Plugin for WordPress by OpenStation
CVE-2026-19775

4.3MEDIUM

What is CVE-2026-19775?

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress allows authenticated users to bypass authorization checks. This vulnerability arises from inadequate verification of user permissions, enabling attackers with custom-level access to view sensitive information such as private posts and unapproved comments. Users can exploit this weakness by enabling specific AI features via the plugin interface, thus gaining further access to restricted content within the WordPress environment.

Affected Version(s)

OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin 0 <= 1.1.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.