Description
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization bypass leading to unauthorized content manipulation
Action: Patch promptly
AI Analysis

Impact

The vulnerability in the Deepak Anand WP Dummy Content Generator plugin results from missing authorization checks, allowing an attacker to bypass security levels and execute privileged actions such as creating, editing, or deleting content. As a result, unauthorized parties can alter the integrity of a WordPress site, compromising the confidentiality and consistency of published material. The flaw aligns with CWE‑862, indicating a breakdown in proper access control enforcement.

Affected Systems

WordPress sites running the WP Dummy Content Generator plugin by Deepak Anand, specifically versions from the initial release up to and including 4.0.0. Any installation of this plugin within that version range is susceptible to the access‑control failure.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, and no EPSS data is available, so the market exploitation probability cannot be precisely quantified. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been documented yet. Exploitation would likely require access to the WordPress admin interface, but the absence of authorisation checks could allow any authenticated user—or potentially any visitor if the plugin’s endpoints are exposed—to manipulate content. Attackers could exploit this flaw to inject malicious content, deface the site, or alter existing posts.

Generated by OpenCVE AI on October 5, 2026 at 11:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Dummy Content Generator plugin to a version newer than 4.0.0, which resolves the access control issue.
  • Disable the plugin’s admin interface or limit its accessibility to administrators only until the patch is in full effect.
  • Audit existing posts and pages for unauthorized changes and revert any tampered content as necessary.

Generated by OpenCVE AI on October 5, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
Title WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:45:02.991Z

Reserved: 2026-04-07T10:59:05.601Z

Link: CVE-2026-39763

cve-icon Vulnrichment

Updated: 2026-10-05T12:44:55.344Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:53.260

Modified: 2026-10-05T13:16:53.217

Link: CVE-2026-39763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses