← Back to overview

A critical unauthenticated privilege escalation vulnerability has been identified in the WordPress Authorizer plugin affecting versions 3.15.1 and earlier. The vulnerability allows unauthenticated attackers to escalate their privileges without requiring any valid credentials. This poses a significant risk to WordPress sites using the affected plugin versions. The issue is tracked as CVE-2026-81294 and has been documented by both the National Vulnerability Database (NVD) and Patchstack. Site administrators are strongly advised to update the Authorizer plugin to a patched version immediately to mitigate the risk of unauthorized privilege escalation.

Affected products

  • WordPress Authorizer Plugin <= 3.15.1

Related CVE's

  • CVE-2026-81294

Categories

  • Identity & Access
  • Web Technologies