Junglewise Threat Intelligence

CVE-2026-42677: Ben Balter WP Document Revisions missing authorization

CVE-2026-42677 · Severity: high · CVSS 7.5 · Published 2026-06-01

Executive brief

WP Document Revisions is a WordPress plugin used for document management and version control. A security flaw in the plugin allows unauthorized individuals to bypass security settings and access documents or perform actions they should not be permitted to see. This could lead to the exposure of sensitive internal documents or business data.

Technical details

A missing authorization vulnerability (CWE-862) exists in the WP Document Revisions plugin for WordPress in versions up to and including 3.8.1. The flaw stems from a failure to properly validate user permissions when accessing document revision history or security levels. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially gaining unauthorized access to sensitive documents or administrative functions. The issue is resolved in version 4.0.0.

Affected products

  • Ben Balter WP Document Revisions <= 3.8.1

Timeline

  • 2026-04-15: other: Reported by Jakub Herman
  • 2026-05-15: advisory: Patchstack advisory published
  • 2026-06-01: disclosed: NVD publication date

References