VYPR
Medium severity6.5NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2026-24944

CVE-2026-24944

Description

Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe2: from n/a through <= 10.44.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Subscribe2 plugin <=10.44 has missing authorization, allowing unauthenticated attackers to exploit incorrectly configured access controls.

Vulnerability

Description CVE-2026-24944 is a missing authorization vulnerability in the WordPress plugin Subscribe2, developed by weDevs. The flaw affects all versions from n/a through 10.44 and stems from an incorrectly configured access control security level within the plugin. This broken access control issue means that certain functions do not properly verify user permissions or nonce tokens, leading to a lack of authorization checks [1].

Exploitation

Conditions Attackers can exploit this vulnerability without authentication, as the missing authorization allows any unprivileged user (or even unauthenticated visitors) to execute higher-privileged actions. The attack surface is broad because the vulnerability is present in a widely used WordPress plugin, and it is expected to be used in mass-exploit campaigns targeting thousands of websites regardless of size or popularity [1].

Impact

Successful exploitation grants an attacker the ability to perform actions that should be restricted to higher-privileged users, such as modifying plugin settings or accessing sensitive data. The CVSS v3 base score is 6.5 (Medium), reflecting the moderate severity but high likelihood of exploitation due to the ease of attack and potential for widespread automation [1].

Mitigation

The vulnerability is fixed in version 10.45 or later. Users are advised to update the plugin immediately. For those unable to update, Patchstack provides a mitigation rule to block attacks until the update can be applied. Auto-update can be enabled for vulnerable plugins via Patchstack [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.