Description
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
Published: 2026-08-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AutoNetTV Relay WordPress plugin before version 3.0.14 fails to perform any authentication or capability check when it sets a WordPress administrator authentication cookie during a scheduled content‑synchronization task. An unauthenticated attacker can trigger the due scheduled task—if the task executes before the HTTP response is committed—by simply causing the task to run. This allows the attacker to obtain the site’s administrator session cookie and gain full administrator access without ever supplying credentials. The weakness is effectively an improper access control flaw, equivalent to setting privileged credentials without verifying appropriate rights.

Affected Systems

Any WordPress installation that uses AutoNetTV Relay plugin prior to version 3.0.14 and has the scheduled sync cron configured to run on the server. The flaw persists on any server arrangement where the cron task runs before the HTTP response is finalized, such as default WordPress cron or custom host cron jobs.

Risk and Exploitability

Because the vulnerability requires only that the scheduled task run, an attacker can trigger it remotely if they can cause the cron to execute, making the exploit relatively straightforward. Although no CVSS or EPSS scores are publicly available, the lack of authentication and the potential to obtain an administrator session cookie suggest a high‑severity risk. The CVE is not listed in CISA’s KEV catalog, so there is currently no evidence of widespread exploitation, but the logical exploitation path remains viable in any relevant environment.

Generated by OpenCVE AI on August 10, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AutoNetTV Relay plugin to version 3.0.14 or later to apply the vendor's fix.
  • Disable the scheduled sync cron task or restrict it so that only authenticated administrators can trigger it.
  • Ensure that cron jobs run only within a verified request context or adjust server configuration to prevent tasks from executing before the response is committed.

Generated by OpenCVE AI on August 10, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
Title AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T06:00:14.720Z

Reserved: 2026-06-29T07:57:49.083Z

Link: CVE-2026-13600

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T07:30:14Z

Weaknesses