VYPR
Unrated severityNVD Advisory· Published Aug 1, 2026

Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes

CVE-2026-11882

Description

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.