
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27362 is a Missing Authorization (Broken Access Control) vulnerability in the WP Bakery Autoresponder Addon plugin for WordPress, developed by kamleshyadav. It affects all versions up to and including 1.0.6, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 25, 2025, and published on March 5, 2026, with no official patch available as of the disclosure date. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. Specifically, one or more plugin functions lack proper authentication, authorization, or nonce token validation, enabling unauthenticated users to invoke functionality intended for higher-privileged roles. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit remotely (Patchstack).
Successful exploitation allows unauthenticated attackers to perform actions beyond their intended privilege level, resulting in low integrity and low availability impacts with no confidentiality impact. This could enable unauthorized modification of plugin settings or data, or disruption of plugin functionality on affected WordPress sites. While the individual impact per site is moderate, the vulnerability is considered suitable for mass-exploit campaigns targeting large numbers of WordPress installations simultaneously (Patchstack).
No official patch is available, and Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns against WordPress sites regardless of their size or traffic. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the wild. There is no known public PoC code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing at this time (Patchstack).
No official patch from the plugin developer is available as of the disclosure date. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators are advised to immediately update the plugin if a patched version becomes available, or alternatively disable and remove the WP Bakery Autoresponder Addon plugin until a fix is issued. Consulting your hosting provider or web developer for assistance is recommended if direct remediation is not possible (Patchstack).
The vulnerability was discovered and reported by security researcher Phat RiO through Patchstack's responsible disclosure process. Patchstack classified it as medium priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites. No significant broader media coverage or notable community commentary beyond the Patchstack advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."