Broken Access Control in Horea Radu Materialis Companion Plugin
CVE-2026-24543
4.3MEDIUM
What is CVE-2026-24543?
The Horea Radu Materialis Companion plugin suffers from a Missing Authorization vulnerability, which arises due to incorrectly configured access control settings. This flaw allows unauthorized users to potentially exploit the plugin, resulting in unauthorized access to sensitive functionalities. This vulnerability affects versions of Materialis Companion up to and including 1.3.52, posing a serious risk to WordPress sites utilizing this plugin. It is crucial for site administrators to address this issue promptly to safeguard their applications from unwanted access and data exposure.
Affected Version(s)
Materialis Companion 0 <= 1.3.52