Executive brief
BerqWP is a WordPress plugin used to extend site functionality. The plugin contains an unauthenticated broken access control vulnerability that allows users to access pages or perform actions they should not be authorized to do, such as viewing other users' data. This could result in exposure of sensitive information stored within the WordPress site.
Technical details
BerqWP versions 4.1.15 and earlier contain an unauthenticated broken access control vulnerability classified under OWASP A1. The vulnerability allows unauthenticated attackers to access protected pages or perform unauthorized actions without proper authorization checks, potentially exposing user data or sensitive information. The vulnerability requires no special privileges or user interaction—network access alone is sufficient to exploit it. The issue is fixed in version 4.1.16 and later. Patch is available; affected users should update immediately.
Affected products
- BerqWP BerqWP <=4.1.15
Timeline
- 2026-07-06: disclosed: Vulnerability reported to Patchstack
- 2026-09-16: advisory: Published by Patchstack
- 2026-09-16: patched: Patch available in version 4.1.16