Executive brief
CheckView Automated Testing is a WordPress plugin used for managing automated tests on websites. A security flaw in versions 2.1.0 and earlier allows unauthenticated individuals to bypass security checks and perform actions they are not authorized to do. This could allow an attacker to modify site settings or data, potentially compromising the integrity of the testing environment or the website itself.
Technical details
The CheckView Automated Testing plugin for WordPress (versions up to and including 2.1.0) suffers from a broken access control vulnerability categorized as CWE-862 (Missing Authorization). The flaw allows a remote, unauthenticated attacker to execute functions or actions that should be restricted to higher-privileged users. According to the CVSS vector, the impact is limited to integrity (I:H), suggesting that while data can be modified, it may not be directly exfiltrated or lead to a denial of service. The issue is resolved in version 2.2.0.
Affected products
- CheckView CheckView Automated Testing <= 2.1.0
Timeline
- 2026-05-30: other: Vulnerability reported by researcher sequence_X0
- 2026-06-19: disclosed: Initial disclosure by Patchstack
- 2026-06-25: advisory: NVD publication date
- 2026-06-25: patched: Patch confirmed available in version 2.2.0