Description
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Published: 2026-09-23
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

The Loops & Logic plugin for WordPress contains an unauthenticated broken access control flaw in versions up to 4.2.4. An attacker who can reach the WordPress site can call plugin functions without being logged in and therefore gain access to data or perform actions that should be restricted to administrators. The weakness stems from improper validation of the user's role before executing privileged operations, as identified by CWE‑862. Based on the description, it is inferred that the attack vector is any HTTP request to the plugin's endpoints that does not require authentication.

Affected Systems

The vulnerability affects all installations of the Tangible Loops & Logic plugin version 4.2.4 and earlier. Users deploying the plugin through WordPress should check that the installed version is 4.3.0 or later to mitigate the issue. Based on the description, it is inferred that the scope of affected installations is limited to WordPress sites running Loops & Logic plugin version 4.2.4 or earlier.

Risk and Exploitability

The CVSS score of 7.5 reflects moderate to high severity due to the lack of authentication. While the EPSS score is not available, the flaw can be exploited by any visitor to the site, making it widely exploitable. The vulnerability is not listed in the CISA KEV catalog, but the potential impact of unauthorized data exposure or modification warrants immediate attention. Attackers can trigger the flaw via standard HTTP requests to the plugin's endpoints without authentication, indicating a low barrier to exploitation. Based on the description, it is inferred that exploitation requires only a standard HTTP request and no privileged access.

Generated by OpenCVE AI on September 23, 2026 at 20:28 UTC.

Remediation

Vendor Solution

Update the WordPress Loops & Logic Plugin to the latest available version (at least 4.3.0).


OpenCVE Recommended Actions

  • Update the Loops & Logic WordPress plugin to version 4.3.0 or later.
  • Enforce role‑based access controls so that only administrators can invoke the plugin’s privileged functions.
  • If an upgrade cannot be applied immediately, deactivate or remove the plugin to eliminate the attack surface.

Generated by OpenCVE AI on September 23, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Title WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T18:46:50.844Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:53.637

Modified: 2026-09-23T19:39:08.847

Link: CVE-2026-95604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:30:09Z

Weaknesses