Access Control Flaw in LifePress Plugin by Ashan Perera
CVE-2026-24563
4.3MEDIUM
What is CVE-2026-24563?
A missing authorization vulnerability in the LifePress plugin by Ashan Perera allows malicious users to exploit incorrectly configured access control security levels. This issue affects LifePress versions from the earliest release up to and including version 2.1.3. Attackers could leverage this flaw to gain unauthorized access, compromising user data and system integrity.
Affected Version(s)
LifePress 0 <= 2.2.1