Executive brief
Leyka is a WordPress plugin used to manage fundraising campaigns and donations on websites. A broken authentication flaw in version 3.32.3 and earlier allows attackers with subscriber-level access to bypass login controls and impersonate other user accounts, potentially gaining unauthorized access to sensitive site functions and data.
Technical details
The vulnerability is a broken authentication issue (OWASP A7) affecting WordPress Leyka plugin versions up to 3.32.3. An attacker with subscriber-level privileges can bypass the login system and authenticate as other users without knowing their passwords. This is a privilege escalation attack requiring only a low-privilege account on the affected WordPress installation. As of the advisory date, no official patch was available, though Patchstack provided mitigation rules to block exploitation attempts.
Affected products
- WordPress Leyka <= 3.32.3
Timeline
- 2026-08-20: disclosed: CVE-2026-66677 published on NVD
- 2026-08-19: advisory: Patchstack advisory published