Executive brief
RepairBuddy is a WordPress plugin for managing computer repair operations. The plugin contains an unauthenticated access control flaw that allows unauthorized users to access restricted pages and perform actions they should not be permitted to perform, such as viewing other users' data. An attacker can exploit this without any credentials or authentication.
Technical details
This vulnerability is a broken access control flaw (OWASP A1) in the RepairBuddy WordPress plugin affecting versions up to and including 4.1223. The vulnerability requires no authentication and is network-accessible; attackers can directly access protected resources or perform restricted actions via the affected plugin endpoints. The issue allows unauthorized access to pages and data that should be restricted to authenticated and authorized users. A patch is available in version 4.1224 and later.
Affected products
- Webful Creations RepairBuddy <=4.1223
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: version 4.1224