[HIGH]
·
Self-hosted / private program
·
Disclosed
Unauthenticated broken access control in CheckView Automated Testing (WordPress) up to 2.1.0
Summary
A broken access control in the CheckView Automated Testing WordPress plugin, versions up to and including 2.1.0. A function that performs a privileged action is missing its authorization, authentication and nonce checks, so an unauthenticated visitor can call it.
Impact
Privileged operations executed by anyone who can reach the site. Patchstack rated this 7.5.
Fix
Patched in 2.2.0.
References
- CVE-2026-54844
- Patchstack advisory: patchstack.com/database/wordpress/plugin/checkview/vulnerability/wordpress-checkview-automated-testing-plugin-2-1-0-broken-access-control-vulnerability