CVE WATCH / VULNERABILITY DETAIL

CVE-2026-80338

MEDIUMCVSS 6.8NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline. Exploitation requir

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-80338 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-80338

MEDIUMCVSS 6.8NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline. Exploitation requir

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]