Executive brief
The WPAMS (Apartment Management System) plugin for WordPress is vulnerable to unauthorized data deletion. An individual with a basic 'Subscriber' account can delete arbitrary website content, such as posts, pages, or images. This could lead to significant data loss and disruption of website operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in the WPAMS (Apartment Management System) plugin for WordPress in versions prior to 49.5.3. The flaw allows an authenticated attacker with low-level 'Subscriber' privileges to bypass access controls and delete arbitrary content, including posts and media, from the site. The vulnerability is exploitable over the network without user interaction. Users are advised to update to version 49.5.3 or later to remediate the issue.
Affected products
- mojoomla WPAMS (Apartment Management System) < 49.5.3
Timeline
- 2026-01-24: other: Reported by Denver Jackson
- 2026-04-07: disclosed: Published by Patchstack
- 2026-06-17: advisory: NVD published date