ZeroHour

CVE-2026-81294

niche

Unauthenticated Privilege Escalation in Authorizer WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-81294 is an unauthenticated privilege escalation flaw in the Authorizer WordPress plugin affecting all versions up to and including 3.15.1. Because the issue is reachable without authentication over the network (per the CVSS vector), an attacker can trigger it remotely with no credentials and no user interaction. A successful exploit allows the attacker to elevate their privileges on the affected WordPress site, gaining high-level access with confidentiality, integrity, and availability impact (CVSS 3.1: 9.8, critical). Any WordPress site running Authorizer version 3.15.1 or earlier is affected. As of now there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at a modest 0.3%, so exploitation is not confirmed in the wild.

What to do: Update the Authorizer plugin to the latest release available on WordPress.org (anything newer than 3.15.1) on every affected site, since the flaw is exploitable without authentication. Until patched, treat the plugin as exposed and check site logs for unexpected admin-user creation or privilege changes. If an immediate update is not possible, deactivate the plugin until a fixed version is deployed.

Affected
Authorizer (plugin authors) Authorizer WordPress plugin<= 3.15.1
Estimated exposure
niche≈ a few thousand sites (plugin reported at roughly 3,000+ active installs on WordPress.org) — Authorizer is a niche external-authentication/login plugin whose WordPress.org active-install count is in the low thousands, so the affected install base is plausibly a few thousand sites; the exact number in the data is not stated, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.