Authorization Bypass in Equalize Digital Accessibility Checker for WordPress
CVE-2026-9199

4.3MEDIUM

What is CVE-2026-9199?

The Equalize Digital Accessibility Checker is susceptible to an authorization bypass flaw that affects all versions up to 1.42.1. This vulnerability allows authenticated users with author-level access and above to manipulate accessibility audit records across the entire site. Specifically, an attacker can exploit this flaw by using their own post's issue as an authorization token to alter the audit status of issues not belonging to their posts. By passing largeBatch=true in dismiss-issue requests, they can inadvertently modify accessibility issues site-wide, affecting records tied to administrator-owned posts. Proper validation checks are essential to prevent unauthorized actions and protect site integrity.

Affected Version(s)

Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance 0 <= 1.42.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joy Gilbert
.