Description
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑78291 reveals that the RepairBuddy plugin up to version 4.1223 allows an unauthenticated attacker to invoke actions that should only be available to privileged users. The vulnerability results in privilege escalation within a WordPress site, enabling an attacker to perform administrative operations or access sensitive data without authorization.

Affected Systems

The affected product is Webful Creations RepairBuddy for WordPress, all releases up to and including version 4.1223. WordPress sites that have this plugin installed and have not applied the latest update are vulnerable. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS base score of 5.3 places the flaw in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not known to be widely exploited at this time. Because the flaw is unauthenticated, an attacker can reach the vulnerable functionality via the web interface of the WordPress site, making remote exploitation straightforward. Administrators should consider the risk high relative to the potential for full site compromise, especially when the plugin is used in production environments.

Generated by OpenCVE AI on August 24, 2026 at 12:24 UTC.

Remediation

Vendor Solution

Update the WordPress RepairBuddy Plugin to the latest available version (at least 4.1224).


OpenCVE Recommended Actions

  • Update the RepairBuddy plugin to the latest version (≥ 4.1224).
  • Reconfigure WordPress user roles to reduce unnecessary administrative privileges for the RepairBuddy plugin.
  • Audit the installation directory for RepairBuddy to ensure no residual vulnerable files remain after the update.

Generated by OpenCVE AI on August 24, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Webful Creations
Webful Creations repairbuddy
Wordpress
Wordpress wordpress
Vendors & Products Webful Creations
Webful Creations repairbuddy
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
Title WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Webful Creations Repairbuddy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:11.182Z

Reserved: 2026-08-24T07:38:18.805Z

Link: CVE-2026-78291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T12:16:56.110

Modified: 2026-08-24T12:16:56.110

Link: CVE-2026-78291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T12:45:04Z

Weaknesses