Access Control Vulnerability in ProLancer Element by Patchstack
CVE-2026-28190

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-28190?

The ProLancer Element plugin for WordPress contains a broken access control flaw that allows unauthorized users to access certain features or data. This vulnerability affects all versions up to 1.4.8, enabling potential exploitation if not patched. Users should ensure they are using the latest version to mitigate risks associated with unauthorized access.

Affected Version(s)

ProLancer Element <= 1.4.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamaal ahmed | Patchstack Bug Bounty Program
.