Description
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
Published: 2026-08-31
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WordPress OwnerRez API Plugin up to version 1.2.6 allows users with subscriber privileges to bypass access controls, enabling them to invoke API endpoints that should be restricted. This broken access control, classified as CWE-862, can lead to unauthorized data exposure or manipulation of booking information, potentially impacting confidentiality and integrity of tenant data.

Affected Systems

Affected parties are WordPress installations using the OwnerRez API Plugin version 1.2.6 or earlier. The plugin serves as an interface between WordPress and the OwnerRez booking system. Any site permitting subscriber role access via the plugin is vulnerable, regardless of the WordPress version.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate risk. EPSS is not available, and the issue is not listed in CISA KEV, suggesting no known widespread exploits at this time. Attackers would need to authenticate as a subscriber to exploit the flaw, but the broken controls could allow them to manipulate booking records. The likely attack vector is through the plugin’s API endpoints, accessed by authenticated users who are not authorized to perform those actions. Defenses include restricting API access and enforcing proper role checks.

Generated by OpenCVE AI on August 31, 2026 at 21:24 UTC.

Remediation

Vendor Solution

Update the WordPress OwnerRez API Plugin to the latest available version (at least 1.3.0).


OpenCVE Recommended Actions

  • Update the WordPress OwnerRez API Plugin to version 1.3.0 or later.
  • Ensure that API endpoints enforce proper role checks so that subscriber actions are restricted to appropriate privileges.
  • Monitor API usage for abnormal activity and revoke any compromised subscriber accounts.

Generated by OpenCVE AI on August 31, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
Title WordPress OwnerRez API plugin <= 1.2.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:47.725Z

Reserved: 2026-08-27T12:22:09.412Z

Link: CVE-2026-81758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:51.047

Modified: 2026-08-31T21:17:51.047

Link: CVE-2026-81758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:30:05Z

Weaknesses