Junglewise Threat Intelligence

CVE-2026-81294: WordPress Authorizer privilege escalation

CVE-2026-81294 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Vendors: Wordpress.

Executive brief

The Authorizer plugin for WordPress is vulnerable to privilege escalation that allows unauthenticated attackers to gain administrative control of a WordPress site. An attacker can exploit this vulnerability without needing valid credentials, potentially enabling full site takeover, data theft, malware injection, and reputational damage.

Technical details

The Authorizer WordPress plugin versions 3.15.1 and earlier contain an unauthenticated privilege escalation vulnerability. A low-privileged or unauthenticated attacker can exploit an authentication or authorization flaw to elevate their privileges to administrator level, gaining full control over the WordPress installation. The vulnerability is a network-accessible attack requiring no authentication and no user interaction. An attacker can leverage this to execute arbitrary code, modify site content, exfiltrate data, or deploy malware. The vulnerability is patched in version 3.15.2 and later.

Affected products

  • WordPress Authorizer <=3.15.1

Timeline

  • 2026-09-02: disclosed
  • 2026-09-01: patched: Version 3.15.2 released

References