CVE-2026-81801
moderateMissing Authorization in WP-Stateless lets subscribers change plugin settings
WP-Stateless versions up to and including 4.4.1 contain a missing authorization check (CWE-862) in its settings-change functionality, meaning the plugin does not properly verify that a user has the required capability before allowing configuration changes. An attacker only needs a subscriber-level account on the WordPress site and can trigger the flaw remotely over the network with no user interaction, for example on any site that allows open registration. By changing WP-Stateless settings, the attacker gains high integrity and availability impact (CVSS 3.1: 8.1 High, C:N/I:H/A:H), such as altering how the site stores and serves media, without any confidentiality impact. Any WordPress site running WP-Stateless 4.4.1 or earlier is affected, with risk concentrated on sites that permit subscriber self-registration. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Update WP-Stateless to the latest patched release (anything above 4.4.1) as soon as possible. Until patched, disable or restrict open subscriber registration so untrusted users cannot obtain the low-privilege account needed to exploit the flaw, and review the plugin's storage/CDN settings and logs for unauthorized changes.
| Usability Dynamics WP-Stateless (WordPress plugin) | <= 4.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.