SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-11882

LOW · CVSS 3.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Builderall for WordPress plugin prior to version 3.0.2 is vulnerable due to a lack of session binding for its public OAuth authentication routes, enabling unauthenticated attackers to manipulate the connection flow. This could lead to the unauthorized overwriting of stored third-party integration access tokens, particularly affecting sites already linked to a paid account. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of unauthorized access to sensitive integrations.

CVE
CVE-2026-11882
Severity
LOW
CVSS
3.7
EPSS
0.19%
WordPress

Original NVD Description

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.