Unauthenticated Broken Access Control in Stitch Express Plugin by WordPress
CVE-2026-73394
7.5HIGH
What is CVE-2026-73394?
The Stitch Express plugin for WordPress versions up to 1.9.0 has a vulnerability that allows unauthenticated users to exploit broken access controls. This flaw enables attackers to gain unauthorized access to sensitive information and perform actions that should be restricted. Proper validation and authentication measures are essential to mitigate this risk.
Affected Version(s)
Stitch Express <= 1.9.0