Junglewise Threat Intelligence

CVE-2026-18364: Zportals AJAX authorization bypass allows settings modification

CVE-2026-18364 · Severity: medium · CVSS 4.3 · Published 2026-09-23

Executive brief

The Zportals WordPress plugin before version 6.4.2 fails to verify user permissions on several administrative actions, allowing any logged-in user with a subscriber-level account to modify the plugin's integration settings without authorization. An attacker could potentially reconfigure critical integrations, leading to unauthorized data collection, service disruption, or compromise of connected systems.

Technical details

The plugin lacks both capability checks and nonce validation on multiple AJAX endpoints, enabling broken access control. Subscriber-level users can send direct requests to modify stored integration settings normally restricted to administrators. A low-privilege authenticated user is required; no network-level privileges or user interaction is needed for exploitation.

Affected products

  • Zportals Zportals before 6.4.2

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in version 6.4.2

References

Related threats