Executive brief
CloudSecure WP Security, a WordPress plugin designed to protect websites, contains a flaw that allows unauthorized individuals to bypass security checks. An attacker could exploit this to gain administrative access to the website, potentially leading to full site takeover, data theft, or service disruption. This vulnerability affects all versions up to and including 1.4.7.
Technical details
CloudSecure WP Security (<= 1.4.7) is vulnerable to an authentication bypass using an alternate path or channel (CWE-288). The flaw allows an unauthenticated remote attacker to perform actions that should be restricted to high-privileged users, potentially leading to full administrative access. While the attack vector is network-based and requires no user interaction, the CVSS vector indicates high complexity (AC:H), suggesting specific conditions or configurations must be met for successful exploitation. The vulnerability is addressed in version 1.4.8.
Affected products
- CloudSecure CloudSecure WP Security <= 1.4.7
Timeline
- 2026-03-16: other: Vulnerability reported by researcher 0xzenko
- 2026-05-28: patched: Patch released in version 1.4.8
- 2026-06-15: disclosed: CVE published to NVD