Executive brief
iControlWP is a WordPress plugin used to manage multiple websites from a single dashboard. A critical security flaw allows unauthorized individuals to gain administrative access to a website without needing a password. This could lead to a complete takeover of the site, resulting in data theft, site defacement, or the installation of malicious software.
Technical details
The iControlWP plugin for WordPress is vulnerable to unauthenticated privilege escalation due to incorrect privilege assignment (CWE-266) in versions up to 5.5.3. An attacker can exploit this flaw over the network without any prior authentication or user interaction. By successfully exploiting the vulnerability, a remote actor can escalate their privileges to an administrator level, granting them full control over the affected WordPress installation. The issue is resolved in version 5.5.4.
Affected products
- iControlWP iControlWP <= 5.5.3
Timeline
- 2026-02-11: other: Reported by Jarno Vos
- 2026-04-07: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date