Description
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
Published: 2026-07-02
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw (CWE‑862) in the WordPress POS Entegratör plugin versions 3.7.103 and earlier, enabling unauthenticated users to reach certain plugin features that are normally protected. The description does not list the specific functions that can be accessed, so the exact impact scope is not defined.

Affected Systems

The Gurmehub POS Entegratör plugin for WordPress is affected. Any installation running version 3.7.103 or earlier is vulnerable; sites using these plugin versions are therefore at risk.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. EPSS score is < 1%, so the exploitation probability is very low but non-zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can likely exploit the flaw by sending unauthenticated HTTP requests to the plugin’s endpoints; this inference follows from the description of the vulnerability as unauthenticated broken access control.

Generated by OpenCVE AI on July 22, 2026 at 13:41 UTC.

Remediation

Vendor Solution

Update the WordPress POS Entegratör Plugin to the latest available version (at least 3.8.0).


OpenCVE Recommended Actions

  • Apply the latest plugin version (3.8.0 or newer).
  • Restrict access to the POS Entegratör administrative interface for administrators only.
  • If an immediate update is not possible, disable or delete the plugin until a patched version is available.

Generated by OpenCVE AI on July 22, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Gurmehub
Gurmehub pos Entegratör
Wordpress
Wordpress wordpress
Vendors & Products Gurmehub
Gurmehub pos Entegratör
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
Title WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Gurmehub Pos Entegratör
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:45:40.946Z

Reserved: 2026-06-25T08:03:50.157Z

Link: CVE-2026-57688

cve-icon Vulnrichment

Updated: 2026-07-02T19:45:35.335Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses