Executive brief
The All-In-One Intranet plugin for WordPress, which is used to restrict website access to authorized users or internal staff, contains a security flaw that allows unauthorized individuals to bypass these restrictions. An attacker can exploit this to view private content or sensitive internal data that should be protected. This could lead to the exposure of confidential company information or private member data.
Technical details
The All-In-One Intranet plugin (versions 1.8.1 and below) for WordPress suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to bypass the plugin's primary function of restricting site access, potentially gaining unauthorized access to private pages, posts, or sensitive data intended only for logged-in users. The vulnerability is rated with a CVSS score of 7.5, indicating a high impact on confidentiality. Users are advised to upgrade to version 1.9.0 or later to remediate the issue.
Affected products
- Syed Balkhi Intranet & Private Site – All-In-One Intranet <= 1.8.1
Timeline
- 2026-04-30: other: Reported by researcher dodoh4t
- 2026-06-18: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD dataset
- 2026-06-26: patched: Version 1.9.0 released to address the vulnerability