Junglewise Threat Intelligence

CVE-2026-39607: Wpbens Filter Plus missing authorization in access control

CVE-2026-39607 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Executive brief

Wpbens Filter Plus is a WordPress plugin used to create filters for content and products. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions to perform actions or access data they should not be authorized to see. This could lead to unauthorized changes to site configurations or exposure of internal information.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Wpbens Filter Plus plugin for WordPress through version 1.1.17. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker authenticated as a low-privileged user (such as a Subscriber) can exploit this over the network to perform unauthorized actions or access restricted data. As of the advisory date, no official patch has been confirmed by the vendor.

Affected products

  • Wpbens Filter Plus <= 1.1.17

Timeline

  • 2026-01-06: other: Vulnerability reported by researcher
  • 2026-02-05: advisory: Patchstack published initial advisory
  • 2026-04-08: disclosed: CVE published to NVD

References