Description
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to protected resources
Action: Patch
AI Analysis

Impact

Unauthenticated Broken Access Control in AppMySite plugin versions 3.15.4 and earlier allows an attacker to access or manipulate data that should be restricted to authenticated users. The flaw could lead to unauthorized modification or deletion of content, potential disclosure of sensitive information, and overall compromise of integrity within the affected WordPress site.

Affected Systems

WordPress sites that use the AppMySite plugin version 3.15.4 or earlier are affected. The plugin is a third‑party extension for WordPress installations, and any site running these versions without the update is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. Exploitation is possible over the internet with no authentication, implying a remote attack vector. Because no EPSS score is available and the vulnerability is not listed in the KEV catalog, the exact likelihood of real‑world exploitation is uncertain, but the potential damage warrants prompt remediation.

Generated by OpenCVE AI on September 23, 2026 at 20:59 UTC.

Remediation

Vendor Solution

Update the WordPress AppMySite Plugin to the latest available version (at least 3.15.5).


OpenCVE Recommended Actions

  • Upgrade the WordPress AppMySite plugin to version 3.15.5 or later.
  • Disable or remove the AppMySite plugin if it is not required until the update can be applied.
  • Configure firewall or web‑application rules to block unauthenticated requests to the plugin’s administrative endpoints.

Generated by OpenCVE AI on September 23, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Appmysite
Appmysite appmysite
Wordpress
Wordpress wordpress
Vendors & Products Appmysite
Appmysite appmysite
Wordpress
Wordpress wordpress

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
Title WordPress AppMySite plugin <= 3.15.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Appmysite Appmysite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T19:25:53.895Z

Reserved: 2026-09-21T17:52:29.069Z

Link: CVE-2026-94498

cve-icon Vulnrichment

Updated: 2026-09-23T19:25:50.329Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:49.790

Modified: 2026-09-23T20:17:24.153

Link: CVE-2026-94498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T22:30:10Z

Weaknesses