Sceawere
Vulnerability Detail
CVE-2026-96825UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
All In One WP Security Subscriber Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 3h ago
- Vendor
- David Anderson / Team Updraft
- Product
- All In One WP Security & Firewall
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-09-30T13:17:32.220Z",
"pubdate": "2026-09-30T13:17:32.220Z",
"executiveSummary": "A critical security vulnerability identified as a Subscriber Bypass exists in the All In One WP Security & Firewall plugin, specifically affecting versions 5.4.8 and below.\nThis vulnerability is categorized as an improper access control issue, allowing authenticated users with low-level privileges, such as Subscribers, to bypass intended authorization checks.\nThe flaw stems from insufficient validation of user roles within specific administrative or security-related functional components of the plugin.\nSuccessful exploitation grants an attacker the ability to interact with restricted features or modify security configurations that should be reserved for higher-level roles, such as Administrators.\nThis unauthorized access creates a significant risk profile, potentially leading to the compromise of site security posture, unauthorized data modification, or the elevation of functional privileges.\nThe vulnerability is limited to authenticated users; however, no complex pre-requisites are required beyond possessing an active subscriber-level account on the WordPress installation.\nThis vulnerability highlights a critical failure in enforcing the Principle of Least Privilege (PoLP) within the plugin’s access control logic, posing a severe risk to the integrity and confidentiality of the WordPress security framework.",
"technicalDetails": "The vulnerability resides within the access control verification mechanisms of the All In One WP Security & Firewall plugin, where the authorization logic fails to strictly validate the capabilities or roles of the requesting user before processing sensitive requests.\nRoot Cause: The plugin’s internal routing and action handlers rely on insecure permission checks that do not properly utilize WordPress’s 'current_user_can()' capability checks or nonces required for administrative operations. Consequently, the application assumes that any request directed at certain endpoints is legitimate without verifying the user's privilege level.\nAttack Flow: An attacker possessing a valid Subscriber account initiates a standard authenticated session. By intercepting or crafting specific HTTP POST or GET requests targeting the vulnerable plugin’s administrative functions, the attacker bypasses the client-side UI limitations.\nBecause the server-side code does not re-authenticate the user's role against the target function, the server executes the requested action with elevated authority. An attacker can systematically invoke administrative endpoints that are meant to be restricted to 'manage_options' or similar high-level WordPress capabilities.\nAffected Versions: All In One WP Security & Firewall versions <= 5.4.8 are confirmed to be vulnerable. The flaw is inherent in the architectural implementation of the plugin's core security control modules, which fail to define proper capability gates for non-admin requests.\nAuthentication/Privilege Requirements: The attacker must have a registered account on the target system. While the role required is minimal (Subscriber), the exploitation cannot be performed by an unauthenticated remote user, as the initial session handshake and legitimate authentication are required to proceed to the faulty authorization checks.\nImpact: Upon successful exploitation, an attacker may manipulate firewall settings, disable specific security logging, modify plugin configurations, or potentially trigger administrative actions that lead to further system compromise. The post-exploitation behavior depends entirely on which administrative endpoints the attacker targets within the plugin’s interface, allowing for unauthorized configuration changes that could weaken the overall defensive posture of the WordPress installation."
}