Junglewise Threat Intelligence

CVE-2026-9015: Equalize Digital Accessibility Checker authorization bypass in AJAX handlers

CVE-2026-9015 · Severity: medium · CVSS 4.3 · Published 2026-05-28

Technologies: Equalize Digital Accessibility Checker. Vendors: Equalize Digital.

Executive brief

The Equalize Digital Accessibility Checker plugin for WordPress, which helps websites maintain compliance with accessibility laws, contains a security flaw that allows low-level users to bypass authorization. An authenticated attacker with basic subscriber access can modify or dismiss accessibility audit findings across the entire website. This can compromise the integrity of compliance reports by hiding actual accessibility issues from site administrators.

Technical details

The Equalize Digital Accessibility Checker plugin for WordPress suffers from a missing authorization check (CWE-862) in its AJAX handlers. Specifically, the plugin fails to verify user permissions before allowing modifications to the 'ignore' state, reasons, and comments of accessibility issues. An authenticated attacker with subscriber-level privileges or higher can send crafted requests to modify arbitrary audit findings. By supplying the 'largeBatch=true' parameter, an attacker can perform mass modifications of all rows sharing an 'object' identifier, effectively corrupting the integrity of the site's accessibility audit. The vulnerability is present in versions up to and including 1.42.0 and was addressed in subsequent updates.

Affected products

  • Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance Up to, and including, 1.42.0

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats