CVE-2026-81294
nicheUnauthenticated Privilege Escalation in Authorizer WordPress Plugin
CVE-2026-81294 is an unauthenticated privilege escalation flaw in the Authorizer WordPress plugin affecting all versions up to and including 3.15.1. Because the issue is reachable without authentication over the network (per the CVSS vector), an attacker can trigger it remotely with no credentials and no user interaction. A successful exploit allows the attacker to elevate their privileges on the affected WordPress site, gaining high-level access with confidentiality, integrity, and availability impact (CVSS 3.1: 9.8, critical). Any WordPress site running Authorizer version 3.15.1 or earlier is affected. As of now there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at a modest 0.3%, so exploitation is not confirmed in the wild.
What to do: Update the Authorizer plugin to the latest release available on WordPress.org (anything newer than 3.15.1) on every affected site, since the flaw is exploitable without authentication. Until patched, treat the plugin as exposed and check site logs for unexpected admin-user creation or privilege changes. If an immediate update is not possible, deactivate the plugin until a fixed version is deployed.
| Authorizer (plugin authors) Authorizer WordPress plugin | <= 3.15.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.