Junglewise Threat Intelligence

CVE-2026-24638: Webful Creations RepairBuddy missing authorization in access control

CVE-2026-24638 · Severity: medium · CVSS 4.3 · Published 2026-05-26

Technologies: Webful Creations RepairBuddy. Vendors: Webful Creations.

Executive brief

RepairBuddy is a WordPress plugin used by computer and device repair shops to manage customer orders and business operations. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized modifications to certain site settings or data.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Webful Creations RepairBuddy plugin for WordPress through version 4.1121. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker authenticated with low-level privileges (such as a Subscriber) can exploit this to perform unauthorized actions, potentially leading to data integrity issues. The vulnerability is addressed in version 4.1125.

Affected products

  • Webful Creations RepairBuddy <= 4.1121

Timeline

  • 2025-12-05: other: Reported by researcher Legion Hunter
  • 2026-05-26: advisory: Published by Patchstack and NVD
  • 2026-05-26: patched: Fixed in version 4.1125

References

Related threats