Unauthorized Access in Content Egg Plugin for WordPress
CVE-2026-92424
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 30 September 2026
Badges
What is CVE-2026-92424?
The Content Egg plugin for WordPress fails to verify user authorization when using its bulk content-import feature. This oversight allows users with contributor-level access and above to select import presets intended for privileged users, effectively switching the import process to the identity of the preset author's account. Consequently, this vulnerability enables the storage of arbitrary web scripts without proper filtering, which can be executed when the resulting posts are viewed by any user, exposing them to potential security threats.
Affected Version(s)
Content Egg 0 < 11.9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.