VYPR
Medium severity5.3NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-24982

CVE-2026-24982

Description

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Spectra (Gutenberg blocks) up to 2.19.17 allows unauthenticated access control bypass, enabling mass exploitation.

Vulnerability

Overview CVE-2026-24982 is a missing authorization vulnerability in the Brainstorm Force Spectra plugin (formerly Ultimate Addons for Gutenberg) for WordPress. The issue stems from incorrectly configured access control security levels, allowing an attacker to exploit broken access control mechanisms. This affects all versions from n/a through 2.19.17 [1].

Exploitation

Details The vulnerability is classified as a broken access control issue, meaning there is a missing authorization, authentication, or nonce token check in a function. This could allow an unprivileged user to execute a higher-privileged action without proper authentication. The attack surface is broad, as the plugin is widely used, and the vulnerability can be exploited remotely without any special network position or user interaction [1].

Impact

An attacker exploiting this vulnerability can bypass access controls, potentially gaining unauthorized access to sensitive functionality or data. The CVSS v3 base score is 5.3 (Medium), indicating a moderate severity. However, the vulnerability is noted to be used in mass-exploit campaigns, targeting thousands of thousands of websites, regardless of traffic size or popularity [1].

Mitigation

The vendor has released version 2.19.18 which resolves the issue. Users are strongly advised to update immediately. If unable to update, users should contact their hosting provider or web developer for assistance. Patchstack users can enable auto-update for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.