Executive brief
The Multicollab plugin for WordPress, which provides editorial workflow and collaboration tools, contains a security flaw that allows low-level users to add comments to any collaboration project. This could lead to unauthorized data modification or the injection of unwanted content into private editorial discussions. The issue affects all versions of the plugin up to 5.2.
Technical details
The Multicollab plugin for WordPress is vulnerable to a missing authorization check (CWE-862) within the 'cf_add_comment' function. This flaw exists in all versions up to and including 5.2. An authenticated attacker with Subscriber-level permissions or higher can exploit this by sending a crafted request to add comments to arbitrary collaborations without proper authorization. This allows for unauthorized data modification within the collaboration environment. A patch has been released in subsequent versions to address the missing capability check.
Affected products
- Multicollab Multicollab: Content Team Collaboration and Editorial Workflow Up to and including 5.2
Timeline
- 2026-05-16: advisory: NVD and Wordfence published the vulnerability details.