CVE-2026-27361: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27361 is a Missing Authorization (Broken Access Control) vulnerability in the Responsive Posts Carousel Pro WordPress plugin developed by WebCodingPlace. It affects all versions up to and including 15.1, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 25, 2025, by researcher Phat RiO and published by Patchstack on February 25, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. An unauthenticated remote attacker can send crafted network requests to trigger functionality that should be restricted to higher-privileged users, exploiting the absence of nonce token, authentication, or capability checks. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network (Patchstack).

Impact

Successful exploitation results in a high confidentiality impact, as unauthenticated attackers can access data or perform actions reserved for privileged users on affected WordPress sites. Integrity and availability are not directly impacted per the CVSS scoring. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).

Exploitability

No official patch is currently available for this vulnerability, leaving all sites running Responsive Posts Carousel Pro version 15.1 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-zero probability of exploitation in the wild. No confirmed in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA KEV catalog. Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of their platform (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Responsive Posts Carousel Pro plugin (version ≤ 15.1) using tools like WPScan, Shodan, or by inspecting publicly accessible plugin metadata (e.g., /wp-content/plugins/responsive-posts-carousel-pro/readme.txt).
  2. Identify unprotected endpoint: Analyze the plugin's PHP source code or use fuzzing to locate AJAX actions or REST API endpoints that lack current_user_can(), nonce verification, or authentication checks.
  3. Craft malicious request: Send an unauthenticated HTTP POST or GET request directly to the vulnerable endpoint (e.g., via wp-admin/admin-ajax.php with the appropriate action parameter) without supplying any credentials or nonce tokens.
  4. Exploit access control gap: The server processes the request as if it were from a privileged user, allowing the attacker to read sensitive data or trigger restricted plugin functionality.
  5. Achieve objective: Depending on the exposed functionality, the attacker may exfiltrate configuration data, enumerate posts, or perform other unauthorized operations (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to wp-admin/admin-ajax.php with action parameters associated with the responsive-posts-carousel-pro plugin; repeated requests from a single IP to plugin-specific endpoints.
  • Logs: WordPress access logs showing requests to plugin AJAX handlers without valid nonce tokens or session cookies; HTTP 200 responses to unauthenticated requests that should require authentication.
  • File System: Unexpected modifications to plugin files in /wp-content/plugins/responsive-posts-carousel-pro/; presence of unfamiliar scripts or web shells in the WordPress installation directory.

Mitigation and workarounds

No official patch from the developer (WebCodingPlace) is currently available for versions up to and including 15.1. Site administrators should monitor the WordPress plugin repository for an updated version and apply it immediately upon release. As an interim measure, Patchstack users benefit from a virtual patching rule that blocks exploitation attempts. Alternatively, administrators should consider deactivating and removing the plugin until a fix is released, or restricting access to the WordPress admin-ajax endpoint via firewall rules where feasible (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher Phat RiO, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant vendor statements from WebCodingPlace or broader media coverage have been identified at this time (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management