Description
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthorized access control flaw present in Civi Framework versions up to 2.2.0. It allows a non‑authenticated user to traverse the plugin’s protected endpoints and read or alter data that should be restricted. The weakness is classified as CWE‑862 and could compromise the confidentiality and integrity of the information handled by the plugin, though it does not provide remote code execution.

Affected Systems

The exposed product is the WordPress Civi Framework plugin, maintained by uxper. Any site running version 2.2.0 or earlier is potentially affected. Administrators should verify the plugin version used on their installation and plan to move to a newer, patched release if available.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS figure of less than 1% signals a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation in the wild. An attacker merely needs web‑level access to the site and can craft HTTP requests targeting the plugin’s endpoints to exploit the broken access control without requiring elevated privileges on the underlying system.

Generated by OpenCVE AI on August 3, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Civi Framework WordPress plugin to the latest version to eliminate the access‑control flaw
  • Restrict access to the plugin’s endpoints by applying role‑based permissions or URL restrictions so only authorized users can reach the vulnerable functionality
  • Deploy a web application firewall or similar controls to detect and block suspicious requests aimed at the plugin until the update is performed

Generated by OpenCVE AI on August 3, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Uxper
Uxper civi Framework
Wordpress
Wordpress wordpress
Vendors & Products Uxper
Uxper civi Framework
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Title WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Uxper Civi Framework
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:11:16.484Z

Reserved: 2026-07-22T08:54:08.234Z

Link: CVE-2026-65525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:45.263

Modified: 2026-07-23T16:17:52.167

Link: CVE-2026-65525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses