Junglewise Threat Intelligence

CVE-2026-66677: WordPress Leyka plugin broken authentication

CVE-2026-66677 · Severity: high · CVSS 7.6 · Published 2026-08-20

Vendors: Wordpress.

Executive brief

Leyka is a WordPress plugin used to manage fundraising campaigns and donations on websites. A broken authentication flaw in version 3.32.3 and earlier allows attackers with subscriber-level access to bypass login controls and impersonate other user accounts, potentially gaining unauthorized access to sensitive site functions and data.

Technical details

The vulnerability is a broken authentication issue (OWASP A7) affecting WordPress Leyka plugin versions up to 3.32.3. An attacker with subscriber-level privileges can bypass the login system and authenticate as other users without knowing their passwords. This is a privilege escalation attack requiring only a low-privilege account on the affected WordPress installation. As of the advisory date, no official patch was available, though Patchstack provided mitigation rules to block exploitation attempts.

Affected products

  • WordPress Leyka <= 3.32.3

Timeline

  • 2026-08-20: disclosed: CVE-2026-66677 published on NVD
  • 2026-08-19: advisory: Patchstack advisory published

References