Junglewise Threat Intelligence

CVE-2026-81788: IMPress for IDX Broker broken access control

CVE-2026-81788 · Severity: medium · CVSS 6.3 · Published 2026-09-10

Executive brief

IMPress for IDX Broker is a WordPress plugin that integrates real estate listing data from IDX Broker. A broken access control vulnerability allows subscriber-level users to access pages and perform actions they should not be authorized to perform, including viewing other users' data. An attacker with a subscriber account can exploit this flaw to view confidential customer information or manipulate data on affected websites.

Technical details

This is a broken access control vulnerability (CWE-284) in IMPress for IDX Broker plugin versions 3.3.0 and earlier. The vulnerability allows users with subscriber-level privileges to bypass authorization checks and access pages or perform actions intended only for higher-privilege users. The attack requires a valid subscriber account and is reachable over the network. An attacker can view other users' private data or perform unauthorized actions. The vulnerability has been patched in version 3.3.1 and later.

Affected products

  • IDX Broker IMPress for IDX Broker 3.3.0 and earlier

Timeline

  • 2026-09-10: disclosed
  • 2026-09-08: patched: Version 3.3.1 released

References