Junglewise Threat Intelligence

CVE-2026-65491: Jonathan Daggerhart Query Wrangler broken access control

CVE-2026-65491 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

Query Wrangler, a WordPress plugin used to create custom content queries and displays, contains a security flaw that allows low-privileged users to access restricted functions. An attacker with a basic 'Subscriber' account could potentially view or interact with data they are not authorized to see. This could lead to unauthorized information disclosure or minor operational disruptions on the affected website.

Technical details

A broken access control vulnerability exists in the Query Wrangler plugin for WordPress (versions up to and including 1.5.57) due to missing authorization checks (CWE-862). An attacker authenticated with low-level privileges, such as a Subscriber, can exploit this flaw via network requests to execute functions or access data intended for higher-privileged users. The vulnerability is classified as medium severity with a CVSS score of 4.3, primarily impacting confidentiality. As of the advisory date, no official patch has been released.

Affected products

  • Jonathan Daggerhart (Daggerhart Lab) Query Wrangler <= 1.5.57

Timeline

  • 2026-02-11: other: Vulnerability reported by Que Thanh Tuan
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References