Junglewise Threat Intelligence

CVE-2026-57721: WP Reloaded ApplyOnline missing authorization in access control

CVE-2026-57721 · Severity: medium · CVSS 5.3 · Published 2026-07-01

Executive brief

ApplyOnline is a WordPress plugin used to manage online applications and job postings. A security flaw in the plugin allows unauthorized individuals to bypass intended access controls due to missing authorization checks. This could allow an attacker to perform actions or modify settings that should be restricted to administrators, potentially disrupting application workflows or site configuration.

Technical details

A missing authorization vulnerability (CWE-862) exists in the WP Reloaded ApplyOnline plugin for WordPress in versions up to and including 2.6.7.6. The flaw stems from a failure to implement proper permission checks or nonce validation on certain functions, allowing an unauthenticated remote attacker to execute actions that should require higher privileges. An attacker can exploit this by sending crafted network requests to the affected site. The vulnerability is resolved in version 2.6.8.

Affected products

  • WP Reloaded ApplyOnline up to 2.6.7.6

Timeline

  • 2026-01-22: other: Reported by Jakub Herman
  • 2026-07-01: patched: Version 2.6.8 released
  • 2026-07-01: advisory

References