Broken Access Control in WPComplete by WordPress
CVE-2026-57661
5.4MEDIUM
What is CVE-2026-57661?
The WPComplete plugin versions up to 2.9.5.5 exhibit a broken access control vulnerability that allows unauthorized access to sensitive functionalities. This flaw can be exploited by attackers to gain inappropriate access to user data and perform actions beyond their intended permissions. It's crucial for site administrators using this plugin to address this vulnerability to ensure the integrity and security of their WordPress installation.
Affected Version(s)
WPComplete <= 2.9.5.5
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Md. Minaruzzaman Shovon | Patchstack Bug Bounty Program