Junglewise Threat Intelligence

CVE-2026-42758: Saleswonder Team WebinarIgnition privilege escalation

CVE-2026-42758 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Executive brief

WebinarIgnition, a WordPress plugin used for managing and hosting webinars, contains a critical security flaw that allows unauthorized users to gain administrative privileges. An attacker could exploit this to take full control of the website, potentially leading to data theft, site defacement, or complete service disruption. This vulnerability poses a significant risk to the integrity and reputation of organizations using the plugin.

Technical details

The WebinarIgnition plugin for WordPress is vulnerable to an incorrect privilege assignment (CWE-266) in versions prior to 4.08.253. This flaw allows a remote, unauthenticated attacker to escalate their privileges on the affected WordPress site. By exploiting this vulnerability, an attacker can gain administrative access, enabling full site compromise, including the ability to modify content, access sensitive user data, and install malicious software. The vulnerability is exploitable over the network without user interaction. Users are advised to update to version 4.08.253 or later to mitigate this risk.

Affected products

  • Saleswonder Team: Tobias WebinarIgnition up to 4.08.253

Timeline

  • 2026-05-27: disclosed: Initial publication of the CVE record.
  • 2026-05-27: advisory: Advisory published by Patchstack.

References

Related threats