Junglewise Threat Intelligence

CVE-2026-78291: RepairBuddy broken access control vulnerability

CVE-2026-78291 · Severity: medium · CVSS 5.3 · Published 2026-08-24

Technologies: Webful Creations RepairBuddy. Vendors: Webful Creations.

Executive brief

RepairBuddy is a WordPress plugin for managing computer repair operations. The plugin contains an unauthenticated access control flaw that allows unauthorized users to access restricted pages and perform actions they should not be permitted to perform, such as viewing other users' data. An attacker can exploit this without any credentials or authentication.

Technical details

This vulnerability is a broken access control flaw (OWASP A1) in the RepairBuddy WordPress plugin affecting versions up to and including 4.1223. The vulnerability requires no authentication and is network-accessible; attackers can directly access protected resources or perform restricted actions via the affected plugin endpoints. The issue allows unauthorized access to pages and data that should be restricted to authenticated and authorized users. A patch is available in version 4.1224 and later.

Affected products

  • Webful Creations RepairBuddy <=4.1223

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: version 4.1224

References

Related threats