Missing Authorization in WordPress - #VU151466

 

Missing Authorization in WordPress - #VU151466

Published: September 20, 2026


Vulnerability identifier: #VU151466
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to network-activate an installed network-only plugin.

The vulnerability exists due to missing authorization in the Plugins menu when the menu is exposed to site administrators on a Multisite network. A remote user can network-activate a plugin with the network: true header to network-activate an installed network-only plugin.


Affected software

WordPress

Remediation

Install security update from vendor's website.

WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1

External References

Related Security Bulletins