Access Control Vulnerability in bPlugins PDF Poster
CVE-2026-27416

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2026

What is CVE-2026-27416?

The bPlugins PDF Poster plugin is compromised by a missing authorization vulnerability that enables unauthorized access due to improperly configured access control security levels. This flaw allows attackers to exploit the application and gain access to sensitive resources without correct permissions. Affected versions range from n/a through 2.4.1, making it crucial for users to assess their installations and implement necessary updates or patches to mitigate risks.

Affected Version(s)

PDF Poster <= 2.4.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

benzdeus | Patchstack Bug Bounty Program
.