Description
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify stored SQL queries, which can lead to privilege escalation via arbitrary SQL execution when the modified query is viewed by an administrator.
Published: 2026-07-10
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Business Intelligence Lite plugin for WordPress contains a missing authorization check that allows any authenticated user with Subscriber level access or higher to modify stored SQL queries. Based on the description, the likely attack vector is an authenticated subscriber modifying stored SQL queries through the plugin’s admin interface, which are later executed when an administrator views them, enabling arbitrary SQL execution. The flaw is a classic Missing Authorization vulnerability (CWE-862), leading to privilege escalation, data compromise, and potential full database control.

Affected Systems

This issue affects installations of the WP Business Intelligence Lite plugin from Joey Youngblood on WordPress sites running version 3.2.0 or earlier. All users who can install or activate the plugin, or who have Subscriber or higher roles, are potentially impacted until an update is applied.

Risk and Exploitability

The CVSS score of 8.0 indicates a high severity level. An EPSS score of <1% (0.00348) indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been documented as of now. However, the attack can be performed by any authenticated subscriber via the plugin’s administrative interface, making it relatively straightforward once access is obtained. Based on the description, it is inferred that once a subscriber modifies a stored query, the query is executed when an administrator views it, enabling arbitrary SQL execution and privilege escalation.

Generated by OpenCVE AI on July 29, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Business Intelligence Lite plugin to the latest version that includes proper authorization checks.
  • Review and, if necessary, remove Subscriber or higher-role users from the role that has access to the plugin’s query management interface.
  • Conduct a database integrity audit to verify that no unauthorized SQL queries have been stored, and revert any changes that were made prior to applying the patch.

Generated by OpenCVE AI on July 29, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joeyoungblood
Joeyoungblood wp Business Intelligence Lite
Wordpress
Wordpress wordpress
Vendors & Products Joeyoungblood
Joeyoungblood wp Business Intelligence Lite
Wordpress
Wordpress wordpress

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify stored SQL queries, which can lead to privilege escalation via arbitrary SQL execution when the modified query is viewed by an administrator.
Title WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Joeyoungblood Wp Business Intelligence Lite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-10T18:01:18.569Z

Reserved: 2026-07-09T15:52:05.067Z

Link: CVE-2026-15293

cve-icon Vulnrichment

Updated: 2026-07-10T18:01:15.408Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses