Sceawere
Vulnerability Detail
CVE-2026-97243UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AllAble Connector Subscriber Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- flexyma
- Product
- AllAble Connector
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-30T13:17:36.167Z",
"pubdate": "2026-09-30T13:17:36.167Z",
"executiveSummary": "The AllAble Connector plugin for WordPress, in versions 0.13.4 and below, is susceptible to a broken access control vulnerability. This flaw allows authenticated users with subscriber-level privileges to perform unauthorized actions restricted to higher-privileged users, such as administrators.\nThe vulnerability is classified as an improper authorization issue, which permits horizontal or vertical privilege escalation depending on the reachable functions. By manipulating request parameters or invoking administrative endpoints, an attacker can bypass the intended permission checks.\nThis poses a significant security risk to the integrity and availability of the affected WordPress site, as it grants restricted users the ability to modify system configurations, manage content, or perform administrative tasks that they are not authorized to access. Successful exploitation does not require advanced capabilities; an attacker only needs a standard subscriber account on the target system to initiate the attack, making this a low-complexity vector with high potential impact.\nOrganizations using AllAble Connector 0.13.4 or earlier are exposed to unauthorized administrative actions and should prioritize remediation to prevent exploitation.",
"technicalDetails": "The root cause of this vulnerability lies in insufficient authorization checks within the AllAble Connector codebase. Specifically, the plugin fails to verify the user's role or capabilities before executing administrative functions. In WordPress plugin development, developers often register AJAX actions or REST API endpoints; if these functions rely on client-side requests without server-side validation using current_user_can() or similar permission-checking mechanisms, the endpoint becomes reachable by any authenticated user.\nThe exploitation flow typically begins with an attacker obtaining a valid subscriber session on the WordPress site. Once authenticated, the attacker identifies specific AJAX actions or API endpoints exposed by the AllAble Connector plugin. By crafting malicious HTTP requests (typically POST or GET) targeting these endpoints, the attacker can trigger server-side functions that are intended to be restricted to administrative roles.\nBecause the server-side code does not validate the security nonce or the user's administrative privileges, the underlying business logic executes the requested administrative action on behalf of the attacker. This can include modifying plugin settings, updating data, or manipulating site configuration files, depending on the functionality provided by the specific endpoint exposed. Since the plugin's internal functions implicitly trust the request parameters provided by the user, the attacker can influence the state of the application without restriction.\nThe vulnerability affects versions 0.13.4 and below. The exposure is global for any site where the plugin is active, provided that user registration is enabled, allowing an attacker to self-provision a subscriber account. The lack of proper authorization checks at the entry point of these functions is the primary technical failure. Post-exploitation, the impact ranges from unauthorized information disclosure to complete site compromise, depending on the specific administrative tasks reachable via the vulnerable plugin functions. There is no complex exploitation payload required; the attack is executed through standard, predictable request structures that the plugin is designed to process without validating the caller's privilege level."
}