Authorization Bypass in Equalize Digital Accessibility Checker for WordPress
CVE-2026-9199
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-9199?
The Equalize Digital Accessibility Checker is susceptible to an authorization bypass flaw that affects all versions up to 1.42.1. This vulnerability allows authenticated users with author-level access and above to manipulate accessibility audit records across the entire site. Specifically, an attacker can exploit this flaw by using their own post's issue as an authorization token to alter the audit status of issues not belonging to their posts. By passing largeBatch=true in dismiss-issue requests, they can inadvertently modify accessibility issues site-wide, affecting records tied to administrator-owned posts. Proper validation checks are essential to prevent unauthorized actions and protect site integrity.
Affected Version(s)
Equalize Digital Accessibility Checker β WCAG, ADA, EAA and Section 508 compliance 0 <= 1.42.1