Sceawere

Vulnerability Detail

CVE-2026-62072UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Progress Planner Subscriber Broken Access

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
16h ago
Vendor
Progress Planner
Product
Progress Planner
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T09:17:56.500Z",
  "pubdate": "2026-10-06T09:17:56.500Z",
  "executiveSummary": "The Progress Planner plugin for WordPress, in versions up to and including 1.10.0, is affected by a Broken Access Control vulnerability.\nThis vulnerability allows authenticated users with low-level privileges, such as Subscribers, to perform actions or access data restricted to administrators or other privileged roles.\nThe flaw stems from insufficient server-side authorization checks on sensitive endpoints or administrative functions within the plugin's codebase.\nAn attacker with a Subscriber-level account can exploit this weakness to interact with features they are not authorized to use, potentially leading to unauthorized data modification, administrative configuration changes, or the exposure of sensitive information.\nThe risk is considered significant as it circumvents the intended role-based access control (RBAC) model of the WordPress application.\nSuccessful exploitation does not require advanced technical skill, as the primary requirement is a valid, low-privileged user account, which may be accessible via self-registration if enabled on the target site.\nThe vulnerability highlights a failure to properly validate user capabilities via the current_user_can() WordPress function or equivalent security checks before processing requests.",
  "technicalDetails": "The vulnerability resides in the access control logic of the Progress Planner plugin, where critical functions do not adequately verify the authorization level of the requesting user. In the context of WordPress plugins, this is typically caused by the absence or improper implementation of capability checks within AJAX handlers, REST API endpoints, or administrative menu callback functions.\nWhen a user performs an action within the plugin, the application processes the request server-side. If the code fails to invoke the appropriate WordPress permission checks—such as current_user_can('manage_options')—the plugin implicitly trusts the input and executes the requested logic regardless of the user's assigned role.\nThe attack flow proceeds as follows: First, the attacker authenticates to the target WordPress installation using a Subscriber-level account. Second, the attacker identifies a vulnerable request path used by the plugin for internal operations, such as updating project statuses or modifying administrative settings. Third, the attacker crafts a malicious HTTP request targeting these endpoints. Since the server-side code performs no authorization check, the plugin executes the request using the privileges of the underlying application environment rather than the privileges of the authenticated user.\nThis Broken Access Control permits horizontal or vertical privilege escalation, depending on the specific administrative function exposed. For example, if the vulnerable component handles database operations or configuration updates, a Subscriber might be able to inject arbitrary content, delete project data, or alter the plugin's operational parameters. The impact is exacerbated by the fact that the vulnerable components are often directly accessible via the standard WordPress admin interface or background API processes.\nThe vulnerability affects all versions of Progress Planner up to and including 1.10.0. The lack of granular permission checks constitutes a fundamental security design flaw where the principle of least privilege is not enforced for sensitive administrative operations. Post-exploitation, the attacker maintains the ability to manipulate site data or settings consistently, as long as the underlying vulnerability remains unpatched in the specific plugin version.\nNetwork exposure is restricted to the WordPress installation interface, but since these endpoints are reachable by any logged-in user, the attack surface remains open to any registered account."
}
CVE-2026-62072: Progress Planner Subscriber Broken Access (HIGH Severity, CVSS: 8.8) | Sceawere