
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27361 is a Missing Authorization (Broken Access Control) vulnerability in the Responsive Posts Carousel Pro WordPress plugin developed by WebCodingPlace. It affects all versions up to and including 15.1, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 25, 2025, by researcher Phat RiO and published by Patchstack on February 25, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. An unauthenticated remote attacker can send crafted network requests to trigger functionality that should be restricted to higher-privileged users, exploiting the absence of nonce token, authentication, or capability checks. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network (Patchstack).
Successful exploitation results in a high confidentiality impact, as unauthenticated attackers can access data or perform actions reserved for privileged users on affected WordPress sites. Integrity and availability are not directly impacted per the CVSS scoring. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).
No official patch is currently available for this vulnerability, leaving all sites running Responsive Posts Carousel Pro version 15.1 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-zero probability of exploitation in the wild. No confirmed in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA KEV catalog. Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of their platform (Patchstack).
/wp-content/plugins/responsive-posts-carousel-pro/readme.txt).current_user_can(), nonce verification, or authentication checks.wp-admin/admin-ajax.php with the appropriate action parameter) without supplying any credentials or nonce tokens.wp-admin/admin-ajax.php with action parameters associated with the responsive-posts-carousel-pro plugin; repeated requests from a single IP to plugin-specific endpoints./wp-content/plugins/responsive-posts-carousel-pro/; presence of unfamiliar scripts or web shells in the WordPress installation directory.No official patch from the developer (WebCodingPlace) is currently available for versions up to and including 15.1. Site administrators should monitor the WordPress plugin repository for an updated version and apply it immediately upon release. As an interim measure, Patchstack users benefit from a virtual patching rule that blocks exploitation attempts. Alternatively, administrators should consider deactivating and removing the plugin until a fix is released, or restricting access to the WordPress admin-ajax endpoint via firewall rules where feasible (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher Phat RiO, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant vendor statements from WebCodingPlace or broader media coverage have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."