Sceawere

Vulnerability Detail

CVE-2026-96825UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

All In One WP Security Subscriber Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
David Anderson / Team Updraft
Product
All In One WP Security & Firewall
Attack Type
CWE-290 Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-09-30T13:17:32.220Z",
  "pubdate": "2026-09-30T13:17:32.220Z",
  "executiveSummary": "A critical security vulnerability identified as a Subscriber Bypass exists in the All In One WP Security & Firewall plugin, specifically affecting versions 5.4.8 and below.\nThis vulnerability is categorized as an improper access control issue, allowing authenticated users with low-level privileges, such as Subscribers, to bypass intended authorization checks.\nThe flaw stems from insufficient validation of user roles within specific administrative or security-related functional components of the plugin.\nSuccessful exploitation grants an attacker the ability to interact with restricted features or modify security configurations that should be reserved for higher-level roles, such as Administrators.\nThis unauthorized access creates a significant risk profile, potentially leading to the compromise of site security posture, unauthorized data modification, or the elevation of functional privileges.\nThe vulnerability is limited to authenticated users; however, no complex pre-requisites are required beyond possessing an active subscriber-level account on the WordPress installation.\nThis vulnerability highlights a critical failure in enforcing the Principle of Least Privilege (PoLP) within the plugin’s access control logic, posing a severe risk to the integrity and confidentiality of the WordPress security framework.",
  "technicalDetails": "The vulnerability resides within the access control verification mechanisms of the All In One WP Security & Firewall plugin, where the authorization logic fails to strictly validate the capabilities or roles of the requesting user before processing sensitive requests.\nRoot Cause: The plugin’s internal routing and action handlers rely on insecure permission checks that do not properly utilize WordPress’s 'current_user_can()' capability checks or nonces required for administrative operations. Consequently, the application assumes that any request directed at certain endpoints is legitimate without verifying the user's privilege level.\nAttack Flow: An attacker possessing a valid Subscriber account initiates a standard authenticated session. By intercepting or crafting specific HTTP POST or GET requests targeting the vulnerable plugin’s administrative functions, the attacker bypasses the client-side UI limitations.\nBecause the server-side code does not re-authenticate the user's role against the target function, the server executes the requested action with elevated authority. An attacker can systematically invoke administrative endpoints that are meant to be restricted to 'manage_options' or similar high-level WordPress capabilities.\nAffected Versions: All In One WP Security & Firewall versions <= 5.4.8 are confirmed to be vulnerable. The flaw is inherent in the architectural implementation of the plugin's core security control modules, which fail to define proper capability gates for non-admin requests.\nAuthentication/Privilege Requirements: The attacker must have a registered account on the target system. While the role required is minimal (Subscriber), the exploitation cannot be performed by an unauthenticated remote user, as the initial session handshake and legitimate authentication are required to proceed to the faulty authorization checks.\nImpact: Upon successful exploitation, an attacker may manipulate firewall settings, disable specific security logging, modify plugin configurations, or potentially trigger administrative actions that lead to further system compromise. The post-exploitation behavior depends entirely on which administrative endpoints the attacker targets within the plugin’s interface, allowing for unauthorized configuration changes that could weaken the overall defensive posture of the WordPress installation."
}
CVE-2026-96825: All In One WP Security Subscriber Bypass (MEDIUM Severity, CVSS: 4.2) | Sceawere