A critical unauthenticated privilege escalation vulnerability has been identified in the WordPress Authorizer plugin affecting versions 3.15.1 and earlier. The vulnerability allows unauthenticated attackers to escalate their privileges without any authentication, posing a significant security risk to WordPress sites using this plugin. The flaw has been assigned CVE-2026-81294 and is documented in both the NVD and Patchstack databases. Sites running Authorizer plugin up to and including version 3.15.1 are vulnerable. Users are advised to update to a patched version as soon as available to mitigate the risk of exploitation.