CVE-2026-27362
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27362 is a Missing Authorization (Broken Access Control) vulnerability in the WP Bakery Autoresponder Addon plugin for WordPress, developed by kamleshyadav. It affects all versions up to and including 1.0.6, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 25, 2025, and published on March 5, 2026, with no official patch available as of the disclosure date. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. Specifically, one or more plugin functions lack proper authentication, authorization, or nonce token validation, enabling unauthenticated users to invoke functionality intended for higher-privileged roles. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit remotely (Patchstack).

Impact

Successful exploitation allows unauthenticated attackers to perform actions beyond their intended privilege level, resulting in low integrity and low availability impacts with no confidentiality impact. This could enable unauthorized modification of plugin settings or data, or disruption of plugin functionality on affected WordPress sites. While the individual impact per site is moderate, the vulnerability is considered suitable for mass-exploit campaigns targeting large numbers of WordPress installations simultaneously (Patchstack).

Exploitability

No official patch is available, and Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns against WordPress sites regardless of their size or traffic. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the wild. There is no known public PoC code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing at this time (Patchstack).

Mitigation and workarounds

No official patch from the plugin developer is available as of the disclosure date. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators are advised to immediately update the plugin if a patched version becomes available, or alternatively disable and remove the WP Bakery Autoresponder Addon plugin until a fix is issued. Consulting your hosting provider or web developer for assistance is recommended if direct remediation is not possible (Patchstack).

Community reactions

The vulnerability was discovered and reported by security researcher Phat RiO through Patchstack's responsible disclosure process. Patchstack classified it as medium priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites. No significant broader media coverage or notable community commentary beyond the Patchstack advisory has been identified (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14805HIGH8.8
  • consulting
NoYesSep 15, 2026
CVE-2026-75983HIGH7.5
  • wp-event-solution
NoYesSep 15, 2026
CVE-2026-90650HIGH7.2
  • motopress-hotel-booking-lite
NoYesSep 15, 2026
CVE-2026-89141MEDIUM6.5
  • ai-engine
NoYesSep 15, 2026
CVE-2026-15609MEDIUM6.4
  • bridge
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management