Sceawere
Vulnerability Detail
CVE-2026-105062UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Admin Audit Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 10h ago
- Vendor
- Brandtoss
- Product
- WP Admin Audit
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T09:17:11.000Z",
"pubdate": "2026-10-05T09:17:11.000Z",
"executiveSummary": "The Brandtoss WP Admin Audit plugin, versions 1.2.17 and earlier, is susceptible to a missing authorization vulnerability.\nThis flaw resides in the plugin's access control implementation, allowing unauthorized users to interact with sensitive administrative functionality.\nThe vulnerability type is categorized as Improper Access Control (Missing Authorization).\nImpact includes potential unauthorized access to audit logs or sensitive configuration settings depending on the specific endpoint exposed.\nAn unauthenticated or low-privileged attacker can exploit this misconfiguration to bypass intended security boundaries.\nThe vulnerability allows an attacker to perform actions that should be restricted to authenticated administrative users, thereby undermining the integrity and confidentiality of the audit trail.\nNo complex exploitation requirements are noted, suggesting the flaw is reachable through standard HTTP requests directed at the vulnerable interface.",
"technicalDetails": "The core of the vulnerability is the absence of adequate authorization checks within the WP Admin Audit plugin's request handling logic.\nWhen a request is made to specific administrative actions or API endpoints defined by the plugin, the application fails to verify the current user's session, capabilities, or administrative privileges before executing the requested operation.\nIn WordPress plugin development, security functions such as current_user_can() or nonce validation (wp_verify_nonce()) are essential for ensuring that only authorized users can trigger administrative functions.\nThe vulnerability indicates that the plugin lacks these necessary checks on the affected code paths, allowing any remote user, regardless of their authenticated state, to invoke these functions.\nThe attack flow typically involves an attacker identifying the specific HTTP endpoint associated with the audit functionality. Upon discovery, the attacker crafts a malicious request targeted at these endpoints.\nBecause the plugin does not validate the sender's identity or permissions, the server processes the request as if it originated from an authorized administrator.\nThe attack does not require advanced technical capabilities, as the absence of authorization checks permits direct execution through common HTTP GET or POST methods.\nThe post-exploitation impact includes the unauthorized disclosure of sensitive audit data, which may reveal internal site activity, user behavioral patterns, or configuration details that an attacker could use for further reconnaissance or malicious operations within the WordPress environment.\nFurthermore, if the vulnerable endpoints allow for the modification of settings or logs, an attacker could potentially manipulate or delete audit records, effectively hiding unauthorized actions and disrupting the integrity of the security audit process.\nThe vulnerability is present across all versions from n/a through 1.2.17. It is fundamentally an access control flaw resulting from a failure to enforce the principle of least privilege, allowing actors outside the administrative security perimeter to operate within the plugin's functional scope."
}