
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1987 is an Insecure Direct Object Reference (IDOR) vulnerability in the Scheduler Widget plugin for WordPress, affecting all versions up to and including 0.1.6. The flaw allows authenticated attackers with Subscriber-level access or higher to modify any scheduler event by manipulating the id parameter, bypassing ownership verification. It was published on February 14, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), a form of Insecure Direct Object Reference. The vulnerable function scheduler_widget_ajax_save_event() lacks proper authorization checks and ownership verification when processing event update requests — it accepts a user-supplied id parameter and performs the update without confirming the requesting user owns the targeted event. An attacker with at minimum a Subscriber-level WordPress account can craft an AJAX request with an arbitrary event ID to overwrite another user's event data (Feedly, CWE-639).
Successful exploitation allows an authenticated attacker to modify any event managed by the Scheduler Widget plugin, regardless of ownership. This results in integrity and limited availability impacts — event data can be altered or corrupted — but there is no confidentiality impact as the vulnerability does not expose sensitive data. The scope is limited to the WordPress site's scheduler functionality and does not provide a path to remote code execution or lateral movement (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1987. The vulnerability requires authentication (Subscriber-level or above), which reduces the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.042%, indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
/wp-admin/admin-ajax.php) targeting the scheduler_widget_ajax_save_event action, supplying an arbitrary id parameter corresponding to another user's event./wp-admin/admin-ajax.php with the action=scheduler_widget_ajax_save_event parameter from a low-privilege user account, particularly with varying id values in rapid succession.WordPress site administrators should update the Scheduler Widget plugin to a version beyond 0.1.6 that includes proper authorization and ownership checks in the scheduler_widget_ajax_save_event() function. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Additionally, restricting user registration or limiting Subscriber-level account creation can reduce the attack surface (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."