Sceawere
Vulnerability Detail
CVE-2026-5727UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Hello Plus Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- elemntor
- Product
- Hello Plus
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T05:16:40.017Z",
"pubdate": "2026-10-10T05:16:40.017Z",
"executiveSummary": "The Hello Plus WordPress plugin is susceptible to an authorization bypass vulnerability affecting all versions up to and including 1.7.7.\nThe vulnerability stems from inadequate access control enforcement during administrative operations related to header and footer template management.\nThe flaw allows authenticated users possessing Contributor-level privileges or higher to perform unauthorized actions, specifically publishing their own templates and modifying the status of templates owned by higher-privileged administrators.\nThis represents a significant security risk, as it permits lateral movement within the template management interface and allows attackers to override site-wide configurations.\nExploitation requires an active, authenticated account with at least Contributor permissions; the vulnerability is accessible through the standard WordPress dashboard interface without requiring external network exposure.\nImpact includes potential unauthorized site-wide content injection or modification of active design elements, posing risks to site integrity and potential cross-site scripting (XSS) vectors if headers/footers permit malicious script embedding.",
"technicalDetails": "The root cause of this vulnerability is an improper access control check within the Hello Plus plugin's backend logic. Specifically, the plugin functions responsible for saving, updating, and publishing Hello+ header/footer templates fail to validate the 'capability' of the requesting user against the target resource.\nIn the WordPress environment, 'Contributor' level users are typically restricted from publishing posts or modifying content belonging to other users. However, the affected plugin components fail to enforce these WordPress security roles during the template submission process.\nThe attack flow begins when an attacker, authenticated as a Contributor, sends a crafted HTTP POST request to the administrative endpoints defined by the Hello Plus plugin. Because the backend code lacks a robust authorization check (e.g., current_user_can() validation), the plugin processes these requests as legitimate administrative actions.\nThe exploitation allows an attacker to publish their own header/footer templates, which may then be rendered on the frontend of the site depending on the active plugin settings. Furthermore, an attacker can manipulate the state of existing templates, including drafting or overriding templates previously configured by site administrators. This is particularly critical as it allows for the unauthorized alteration of site-wide visual elements.\nThe vulnerable component involves the internal template management handler responsible for CRUD (Create, Read, Update, Delete) operations on Hello+ objects. By manipulating parameters within the AJAX or POST request—often targeting a 'template_id' or status field—the attacker can force the system to perform state transitions that should be restricted to 'Administrator' or 'Editor' roles.\nSince the plugin does not verify the owner of the template or the authorization level of the user in the context of the requested action, the system blindly executes the state change. Post-exploitation impact may include the deployment of unauthorized headers or footers which, if the template system supports raw HTML or script input, could result in Stored Cross-Site Scripting (XSS) attacks impacting all frontend visitors to the site."
}