Junglewise Threat Intelligence

CVE-2026-39584: Webful Creations RepairBuddy broken access control in WordPress plugin

CVE-2026-39584 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Webful Creations RepairBuddy. Vendors: Webful Creations.

Executive brief

RepairBuddy, a WordPress plugin used for managing computer repair shop operations, contains a security flaw that allows users with low-level 'Subscriber' accounts to access information they should not be able to see. This could lead to the unauthorized exposure of sensitive business or customer data. Business owners should update the plugin to prevent unauthorized users from bypassing internal access restrictions.

Technical details

A broken access control vulnerability exists in the RepairBuddy plugin for WordPress (versions 4.1132 and earlier) due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw over the network to access sensitive data that should be restricted to higher-privileged roles. The vulnerability stems from a failure to validate user permissions before executing specific functions or returning data. The issue is resolved in version 4.1133.

Affected products

  • Webful Creations RepairBuddy <= 4.1132

Timeline

  • 2026-02-17: other: Vulnerability reported by researcher
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-04-20: patched: Version 4.1133 released
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats