Description
The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export functionality (download_settings function) which is registered on the plugins_loaded hook and explicitly allows execution on non-admin (public) pages. The function exports all plugin configuration settings including the protection_password field, which is stored in plaintext. This makes it possible for unauthenticated attackers to retrieve the PDF protection password by accessing the /?export-meeting-list=1 endpoint.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Information Disclosure (CWE-862)
Action: Patch
AI Analysis

Impact

The Bread WordPress plugin lacks an authentication and authorization check on its settings export function, enabling any visitor to trigger an export of all plugin configuration data, including the plaintext PDF protection password. This flaw permits the retrieval of sensitive configuration through a public endpoint, potentially allowing attackers to compromise the site or expose confidential information. The missing authorization is a CWE-862 vulnerability.

Affected Systems

WordPress sites running the Bread plugin from vendor radius314 with versions up to and including 2.9.12 are affected. The vulnerability is present in all releases that contain the export_meeting_list endpoint, specifically the download_settings function registered on the plugins_loaded hook.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability simply by making an unauthenticated HTTP request to the /?export-meeting-list=1 endpoint; no additional credentials or privileges are required. This is a missing authorization weakness (CWE-862).

Generated by OpenCVE AI on September 20, 2026 at 00:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Bread plugin to the latest version (2.9.13 or newer) that remediates the missing authorization check in the export functionality.
  • If an upgrade is not immediately possible, block unauthenticated HTTP requests to the /?export-meeting-list=1 endpoint using a firewall rule or .htaccess restriction to prevent the settings export from being triggered.
  • Review and remove any publicly accessible export scripts or endpoints in the plugin, and confirm that the protection_password field is no longer exported or accessible without administrative authentication.

Generated by OpenCVE AI on September 20, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Radius314
Radius314 bread
Wordpress
Wordpress wordpress
Vendors & Products Radius314
Radius314 bread
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export functionality (download_settings function) which is registered on the plugins_loaded hook and explicitly allows execution on non-admin (public) pages. The function exports all plugin configuration settings including the protection_password field, which is stored in plaintext. This makes it possible for unauthenticated attackers to retrieve the PDF protection password by accessing the /?export-meeting-list=1 endpoint.
Title Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Radius314 Bread
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:24.602Z

Reserved: 2026-03-24T21:24:56.620Z

Link: CVE-2026-4792

cve-icon Vulnrichment

Updated: 2026-09-19T13:54:46.659Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.047

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-4792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:39Z

Weaknesses