ZeroHour

CVE-2026-81801

moderate

Missing Authorization in WP-Stateless lets subscribers change plugin settings

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

WP-Stateless versions up to and including 4.4.1 contain a missing authorization check (CWE-862) in its settings-change functionality, meaning the plugin does not properly verify that a user has the required capability before allowing configuration changes. An attacker only needs a subscriber-level account on the WordPress site and can trigger the flaw remotely over the network with no user interaction, for example on any site that allows open registration. By changing WP-Stateless settings, the attacker gains high integrity and availability impact (CVSS 3.1: 8.1 High, C:N/I:H/A:H), such as altering how the site stores and serves media, without any confidentiality impact. Any WordPress site running WP-Stateless 4.4.1 or earlier is affected, with risk concentrated on sites that permit subscriber self-registration. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Update WP-Stateless to the latest patched release (anything above 4.4.1) as soon as possible. Until patched, disable or restrict open subscriber registration so untrusted users cannot obtain the low-privilege account needed to exploit the flaw, and review the plugin's storage/CDN settings and logs for unauthorized changes.

Affected
Usability Dynamics WP-Stateless (WordPress plugin)<= 4.4.1
Estimated exposure
moderate≈30,000+ sites (WP-Stateless is listed with roughly 30,000+ active installs on WordPress.org) — The estimate uses the plugin's publicly listed active-install count in the WordPress.org directory, which places exposure in the tens of thousands of WordPress sites, with actual exploitability limited to sites that expose subscriber…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.