Description
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Breakdance: from n/a before 2.7.
Published: 2026-08-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a missing authorization check in the WordPress Breakdance plugin. When security levels are incorrectly configured, the plugin fails to enforce proper access controls, allowing users to interact with functions that should be restricted. This flaw can lead to unauthorized viewing or modification of content, form settings, or other sensitive data managed through the plugin, potentially compromising the integrity and confidentiality of the website’s configuration.

Affected Systems

The issue targets the Soflyy Breakdance plugin for WordPress, affecting every installation of the plugin that is running any version prior to 2.7. Any WordPress site that has installed Breakdance 2.6.1 or earlier is susceptible.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity of exploitation. EPSS data is not available, and the vulnerability is not yet listed in CISA's KEV catalog, suggesting no publicly known exploits to date. The likely attack vector requires an authenticated user with at least some level of access to the WordPress admin interface; such a user could exploit the configuration flaw to gain unauthorized control over plugin functions. The exploitation effort is relatively low, given that the flaw arises from missing ACL checks rather than a complex sequence of inputs.

Generated by OpenCVE AI on August 6, 2026 at 15:06 UTC.

Remediation

Vendor Solution

Update the WordPress Breakdance plugin to the latest available version (at least 2.7).


OpenCVE Recommended Actions

  • Update the WordPress Breakdance plugin to version 2.7 or later.
  • Verify that the plugin’s feature permissions are correctly configured, ensuring only privileged users can modify layout or form settings.
  • If a plugin update is not immediately possible, restrict access to Breakdance’s administrative pages by using a role-based restriction plugin or server‑level authentication.

Generated by OpenCVE AI on August 6, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Soflyy
Soflyy breakdance
Wordpress
Wordpress wordpress
Vendors & Products Soflyy
Soflyy breakdance
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
Title WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Soflyy Breakdance
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T13:49:42.133Z

Reserved: 2026-07-22T08:54:17.066Z

Link: CVE-2026-65551

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-06T13:18:21.417

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-65551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:15:12Z

Weaknesses