Description
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Published: 2026-08-19
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains an unauthenticated broken access control flaw that lets an attacker perform administrative actions without proper credentials. This could lead to unauthorized content manipulation, data disclosure or modification, and potentially further compromise of the WordPress site.

Affected Systems

Stitch Express plugin for WordPress, versions 1.9.0 or older installed on any WordPress installation.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. EPSS information is not available and it is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports. Nevertheless, because the flaw permits unauthenticated users to bypass authorization controls, it can be leveraged from any network location that can reach the affected WordPress installation.

Generated by OpenCVE AI on August 19, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Stitch Express plugin to the latest version (1.9.1 or newer) to eliminate the flaw.
  • If an upgrade is not immediately possible, disable the plugin until a patched version is available.
  • Verify that all plugin-provided endpoints require proper authentication and audit other plugins for similar access control weaknesses.

Generated by OpenCVE AI on August 19, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Title WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T15:38:15.797Z

Reserved: 2026-08-12T14:10:08.047Z

Link: CVE-2026-73394

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T13:18:08.670

Modified: 2026-08-19T16:19:09.617

Link: CVE-2026-73394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T20:45:17Z

Weaknesses