Authentication Bypass in WordPress Plugin by Vendor
CVE-2026-59506

9.3CRITICAL

What is CVE-2026-59506?

This vulnerability allows an attacker to exploit a missing authentication mechanism in certain WordPress plugins, potentially granting unauthorized access to critical functions. Without proper authentication, malicious actors could manipulate essential aspects of the web application without the need for valid credentials, increasing the risk of compromise. Developers must ensure robust authentication processes to mitigate these risks and protect user data.

Affected Version(s)

Portal Generator addon to Priority ERP (developed by Soft Solutions) All versions without Priwall v3

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HackersEye
.