Description
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to bypass access controls and view, create, or modify subscriber data within the WordPress WP ERP plugin. This broken access control can lead to unauthorized disclosure and alteration of subscriber personal information. The CVSS score of 6.5 indicates a moderate risk, reflecting the potential impact on confidentiality and integrity of subscriber data.

Affected Systems

The issue affects installations of the weDevs WP ERP plugin version 1.17.5 or earlier. Any WordPress site that has this plugin active and has not applied the patches provided by the vendor is potentially vulnerable.

Risk and Exploitability

With an EPSS score of less than 1% and not listed in the KEV catalog, the probability of exploitation remains low. Attackers can forge or manipulate HTTP requests targeting subscriber management endpoints, exploiting the broken access control to gain unauthorized access to subscriber data. The flaw arises from incomplete access‑control checks, allowing crafted requests to bypass legitimate permission checks.

Generated by OpenCVE AI on August 3, 2026 at 22:21 UTC.

Remediation

Vendor Solution

Update the WordPress WP ERP Plugin to the latest available version (at least 1.17.6).


OpenCVE Recommended Actions

  • Upgrade the WordPress WP ERP plugin to version 1.17.6 or later to remediate the broken access control flaw.
  • Review and enforce role‑based access controls for subscriber management functions to ensure only authorized users can view or modify subscriber data.
  • Enable and monitor logging for subscriber‑related requests to detect unauthorized activity.

Generated by OpenCVE AI on August 3, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs wp Erp
Wordpress
Wordpress wordpress
Vendors & Products Wedevs
Wedevs wp Erp
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Title WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wedevs Wp Erp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T16:00:09.956Z

Reserved: 2026-07-05T21:27:42.076Z

Link: CVE-2026-59522

cve-icon Vulnrichment

Updated: 2026-07-23T16:00:05.569Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:32.347

Modified: 2026-07-23T16:17:29.650

Link: CVE-2026-59522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses