Description
Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects ApplyOnline: from n/a through 2.6.7.6.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing Authorization flaw, identified as CWE‑862, in the WP Reloaded ApplyOnline plugin that allows attackers to bypass the plugin’s configured access control security levels. The description does not clarify what specific functions become accessible once the intended authorization checks are circumvented, but the flaw permits gaining higher privileges within the plugin’s administrative interface.

Affected Systems

ApplyOnline, distributed by WP Reloaded, is affected in all releases from the earliest version through 2.6.7.6. Any WordPress site that installs this plugin at a version equal to or older than 2.6.7.6 is exposed to the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity level, while the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires sending crafted HTTP requests to the plugin’s protected administrative endpoints to bypass the authorization checks, with no additional prerequisites beyond access to these endpoints.

Generated by OpenCVE AI on July 17, 2026 at 12:23 UTC.

Remediation

Vendor Solution

Update the WordPress ApplyOnline Plugin to the latest available version (at least 2.6.8).


OpenCVE Recommended Actions

  • Update the ApplyOnline plugin to version 2.6.8 or later, which contains the vendor‑provided fix.
  • Restrict the plugin’s administrative features to users with administrator access.
  • If an immediate upgrade cannot be performed, temporarily deactivate or uninstall the ApplyOnline plugin until a patched version is available.

Generated by OpenCVE AI on July 17, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Reloaded
Wp Reloaded applyonline
Vendors & Products Wordpress
Wordpress wordpress
Wp Reloaded
Wp Reloaded applyonline

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.
Title WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wp Reloaded Applyonline
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T18:04:55.782Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57721

cve-icon Vulnrichment

Updated: 2026-07-01T18:04:52.061Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T12:30:05Z

Weaknesses