Impact
CVE‑2026‑78291 reveals that the RepairBuddy plugin up to version 4.1223 allows an unauthenticated attacker to invoke actions that should only be available to privileged users. The vulnerability results in privilege escalation within a WordPress site, enabling an attacker to perform administrative operations or access sensitive data without authorization.
Affected Systems
The affected product is Webful Creations RepairBuddy for WordPress, all releases up to and including version 4.1223. WordPress sites that have this plugin installed and have not applied the latest update are vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS base score of 5.3 places the flaw in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not known to be widely exploited at this time. Because the flaw is unauthenticated, an attacker can reach the vulnerable functionality via the web interface of the WordPress site, making remote exploitation straightforward. Administrators should consider the risk high relative to the potential for full site compromise, especially when the plugin is used in production environments.
OpenCVE Enrichment