Description
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Published: 2026-08-06
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Staff Training plugin for WordPress versions up to 1.0.7 contains an unauthenticated broken access control flaw. An attacker who can reach the plugin’s URLs can invoke privileged operations such as creating, editing, or deleting training records without authentication. This compromises the integrity of the training data and can expose sensitive information to the attacker. The vulnerability is a classic example of CWE‑862, where insufficient access checks allow unauthorized use of protected functionality.

Affected Systems

Any WordPress installation that has the Staff Training plugin installed at version 1.0.7 or earlier is affected. The plugin provides administrative pages for managing staff training content; no explicit version information beyond the stated cutoff is available, so all prior releases are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, primarily due to the lack of authentication required for exploitation and the impact on data integrity. The EPSS score is not available, so the probability of exploitation is unknown, but the clear path through the web interface suggests that attacks could be straightforward. The vulnerability is not currently listed in the CISA KEV catalog, meaning no confirmed widespread exploitation has been documented. The likely attack vector is through a standard HTTP request to the plugin’s back‑end URLs, requiring no credentials and no special network conditions.

Generated by OpenCVE AI on August 6, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Staff Training plugin to the latest available version (>=1.0.8) to apply the vendor‑supplied fix.
  • If no newer version exists, disable or remove the plugin to eliminate the vulnerable functionality.
  • Apply additional access control by restricting the plugin's admin URLs to authenticated WordPress administrators, e.g., using a firewall rule or WordPress role‑based access plugins.

Generated by OpenCVE AI on August 6, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Title WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:29.397Z

Reserved: 2026-07-22T08:54:12.816Z

Link: CVE-2026-65541

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses