Description
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
Published: 2026-06-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CheckView Automated Testing plugin for WordPress contains a flaw classified as CWE‑862 that allows unauthenticated users to access and modify privileged plugin endpoints. Attackers can send HTTP requests to the plugin’s API without logging in, enabling them to change test configurations, tamper with settings, or read sensitive data stored by the plugin. The CVE description does not state the full extent of potential damage, so the impact is limited to the privileges granted by the plugin’s internal interfaces.

Affected Systems

The vendor is CheckView, product CheckView Automated Testing plugin for WordPress. Versions up to and including 2.1.0 are affected; versions 2.2.0 and later include the fix. No other vendors or products are listed.

Risk and Exploitability

A CVSS score of 7.5 classifies the vulnerability as high severity, indicating a significant risk if explored. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests to the plugin’s endpoints, which does not require any prior authentication or privileges. Attackers who can reach the site may exploit this flaw by crafting requests that bypass the plugin’s access checks, potentially disrupting site functionality or altering configuration settings.

Generated by OpenCVE AI on June 25, 2026 at 16:50 UTC.

Remediation

Vendor Solution

Update the WordPress CheckView Automated Testing Plugin to the latest available version (at least 2.2.0).


OpenCVE Recommended Actions

  • Update the CheckView Automated Testing plugin to version 2.2.0 or newer to eliminate the vulnerability.
  • If an update cannot be applied immediately, restrict external access to the plugin’s API endpoints by enforcing authentication or limiting IP ranges using firewall rules or .htaccess restrictions.
  • Review all WordPress sites that use older plugin versions for unauthorized configuration changes or malware and strengthen role‑based permissions and audit logs.

Generated by OpenCVE AI on June 25, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
Title WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-25T13:12:35.546Z

Reserved: 2026-06-16T09:22:02.525Z

Link: CVE-2026-54844

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T17:00:11Z

Weaknesses