CVE-2026-1987: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1987 is an Insecure Direct Object Reference (IDOR) vulnerability in the Scheduler Widget plugin for WordPress, affecting all versions up to and including 0.1.6. The flaw allows authenticated attackers with Subscriber-level access or higher to modify any scheduler event by manipulating the id parameter, bypassing ownership verification. It was published on February 14, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), a form of Insecure Direct Object Reference. The vulnerable function scheduler_widget_ajax_save_event() lacks proper authorization checks and ownership verification when processing event update requests — it accepts a user-supplied id parameter and performs the update without confirming the requesting user owns the targeted event. An attacker with at minimum a Subscriber-level WordPress account can craft an AJAX request with an arbitrary event ID to overwrite another user's event data (Feedly, CWE-639).

Impact

Successful exploitation allows an authenticated attacker to modify any event managed by the Scheduler Widget plugin, regardless of ownership. This results in integrity and limited availability impacts — event data can be altered or corrupted — but there is no confidentiality impact as the vulnerability does not expose sensitive data. The scope is limited to the WordPress site's scheduler functionality and does not provide a path to remote code execution or lateral movement (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1987. The vulnerability requires authentication (Subscriber-level or above), which reduces the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.042%, indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Obtain a low-privilege account: Register or obtain a Subscriber-level (or higher) account on the target WordPress site running Scheduler Widget plugin version 0.1.6 or earlier.
  2. Identify event IDs: Browse the site or interact with the scheduler to observe event IDs in AJAX requests (e.g., via browser developer tools or a proxy like Burp Suite). Event IDs may be sequential integers, making enumeration straightforward.
  3. Craft a malicious AJAX request: Construct an authenticated POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) targeting the scheduler_widget_ajax_save_event action, supplying an arbitrary id parameter corresponding to another user's event.
  4. Submit the request: Send the crafted request with valid session cookies. Because the function lacks ownership verification, the server will process the update and overwrite the targeted event's data with attacker-supplied values.
  5. Confirm modification: Verify the targeted event has been altered by viewing the scheduler as an administrator or the event owner (Feedly, CWE-639).

Indicators of compromise

  • Logs: WordPress access logs showing repeated POST requests to /wp-admin/admin-ajax.php with the action=scheduler_widget_ajax_save_event parameter from a low-privilege user account, particularly with varying id values in rapid succession.
  • Application: Unexpected modifications to scheduler events not initiated by their owners; events with altered titles, times, or descriptions without corresponding legitimate user activity.
  • Network: Unusual patterns of authenticated AJAX requests targeting the scheduler endpoint from a single user account across a wide range of event IDs (indicative of enumeration).

Mitigation and workarounds

WordPress site administrators should update the Scheduler Widget plugin to a version beyond 0.1.6 that includes proper authorization and ownership checks in the scheduler_widget_ajax_save_event() function. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Additionally, restricting user registration or limiting Subscriber-level account creation can reduce the attack surface (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management