Junglewise Threat Intelligence

CVE-2026-57781: Sovlix MeetingHub missing authorization in WordPress plugin

CVE-2026-57781 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Executive brief

MeetingHub is a WordPress plugin used for managing meetings and appointments. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to higher-level users. This could lead to unauthorized modifications of meeting data or settings, potentially disrupting business operations or scheduling.

Technical details

A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Sovlix MeetingHub plugin for WordPress through version 1.25.10. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions that should require higher privileges. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.

Affected products

  • Sovlix MeetingHub <= 1.25.10

Timeline

  • 2026-01-10: other: Vulnerability reported by Nabil Irawan
  • 2026-07-02: advisory: Initial advisory published by Patchstack
  • 2026-07-13: disclosed: CVE published to NVD dataset

References