PentestingHere
Log in Join
[HIGH] · Self-hosted / private program · Disclosed

Unauthenticated broken access control in CheckView Automated Testing (WordPress) up to 2.1.0

Youssef Eid Youssef Eid CVE-2026-54844 Patchstack 19 Jun 2026

Summary

A broken access control in the CheckView Automated Testing WordPress plugin, versions up to and including 2.1.0. A function that performs a privileged action is missing its authorization, authentication and nonce checks, so an unauthenticated visitor can call it.

Impact

Privileged operations executed by anyone who can reach the site. Patchstack rated this 7.5.

Fix

Patched in 2.2.0.

References

  • CVE-2026-54844
  • Patchstack advisory: patchstack.com/database/wordpress/plugin/checkview/vulnerability/wordpress-checkview-automated-testing-plugin-2-1-0-broken-access-control-vulnerability