Description
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Authorizer plugin for WordPress, versions up to and including 3.15.3, contains a flaw that allows an unauthenticated attacker to gain administrative privileges on a site. This vulnerability gives the attacker full control over site content, plugin installation, and configuration. The flaw results from insufficient authentication checks on privileged actions, allowing privilege escalation without needing a valid user session.

Affected Systems

The vulnerability affects the WordPress Authorizer plugin, listed under the vendor Paul Ryan. Versions up to and including 3.15.3 are susceptible; the fix is delivered in version 3.16.0 and later.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating a high level of severity. EPSS is not available, and the exploit is not listed in CISA’s KEV catalog. The flaw permits privilege escalation without authentication, meaning an attacker can likely obtain administrative rights by sending crafted requests to the plugin’s interfaces. This can be performed remotely and without direct user interaction. Based on the description, the likely attack vector involves interacting with the plugin’s exposed HTTP endpoints, although the exact path is not explicitly described.

Generated by OpenCVE AI on October 1, 2026 at 16:26 UTC.

Remediation

Vendor Solution

Update the WordPress Authorizer plugin to the latest available version (at least 3.16.0).


OpenCVE Recommended Actions

  • Update the WordPress Authorizer plugin to the latest available version, at least 3.16.0.
  • Audit and restrict user roles to enforce least‑privilege principles, removing any unnecessary administrative accounts before applying the update.
  • Deploy continuous monitoring of administrative actions on the WordPress site to detect suspicious changes quickly.

Generated by OpenCVE AI on October 1, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Title WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:23:37.279Z

Reserved: 2026-10-01T10:21:40.038Z

Link: CVE-2026-103752

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:29.270

Modified: 2026-10-01T16:17:40.327

Link: CVE-2026-103752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment