Description
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
Published: 2026-08-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic unauthenticated broken access control flaw that allows an attacker to read legal texts without any authorization. The weakness is identified as a missing authorization check (CWE‑862), which could let an attacker view or download confidential legal documents stored by the plugin. The impact is the potential exposure of proprietary legal information, with moderate severity as reflected by the CVSS score of 6.5.

Affected Systems

Vulnerable products are the Legal Text Connector of the IT‑Recht Kanzlei WordPress plugin, versions up to and including 1.0.13. The plugin is typically used on websites that host legal documents such as privacy policies or terms of service. Only these versions are affected; any installation running 1.0.14 or newer is considered fixed.

Risk and Exploitability

The high value of the CVSS score indicates that the vulnerability could be successfully exploited by an unauthenticated user to gain access to restricted content. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of protection against unauthenticated access means that a determined attacker could exploit it immediately. The vulnerability is not listed in the CISA KEV catalog, implying that a zero‑day or widespread exploitation has not yet been observed, yet the flaw remains exploitable in the wild.

Generated by OpenCVE AI on August 6, 2026 at 15:37 UTC.

Remediation

Vendor Solution

Update the WordPress Legal Text Connector of the IT-Recht Kanzlei Plugin to the latest available version (at least 1.0.14).


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to the latest plugin version (1.0.14 or later).
  • Review the plugin’s settings and remove any publicly exposed endpoints that are unnecessary for normal operation.
  • If an upgrade is not possible, disable the plugin entirely or restrict access to it by network or application level controls.

Generated by OpenCVE AI on August 6, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared It-recht Kanzlei
It-recht Kanzlei legal Text Connector Of The It-recht Kanzlei
Wordpress
Wordpress wordpress
Vendors & Products It-recht Kanzlei
It-recht Kanzlei legal Text Connector Of The It-recht Kanzlei
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
Title WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

It-recht Kanzlei Legal Text Connector Of The It-recht Kanzlei
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-08T01:55:42.450Z

Reserved: 2026-07-27T09:00:28.156Z

Link: CVE-2026-66452

cve-icon Vulnrichment

Updated: 2026-08-08T01:55:37.461Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:20.460

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:44Z

Weaknesses