VYPR
Medium severity4.3NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-24995

CVE-2026-24995

Description

Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Latest Post Shortcode: from n/a through <= 14.2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Latest Post Shortcode plugin for WordPress ≤14.2.0 has a missing authorization vulnerability allowing unauthorized access to restricted functionality.

Vulnerability

Overview

The Latest Post Shortcode plugin for WordPress, developed by Iulia Cazan, suffers from a missing authorization vulnerability in versions up to and including 14.2.0 [1]. This flaw enables attackers to exploit incorrectly configured access control security levels, potentially granting unauthorized access to functionality that should be restricted to higher-privileged users.

Exploitation

Conditions

The vulnerability arises from a lack of proper authorization checks, such as missing capability checks or nonce verification, in one or more plugin functions [1]. An attacker does not need to be authenticated, or may require only minimal privileges, to exploit this issue. The attack vector is over the network, and no user interaction is typically required beyond the initial request.

Impact

Successful exploitation allows an unprivileged attacker to perform actions normally reserved for higher-privileged users, such as modifying settings or accessing sensitive data. The CVSS score of 4.3 (Medium) reflects a moderate impact, with limited compromise of confidentiality or integrity.

Mitigation

The vulnerability has been addressed in version 14.2.1 of the plugin [1]. Users are strongly advised to update immediately. For those unable to update, temporary measures such as disabling the plugin or seeking assistance from hosting providers may reduce risk. The vendor notes that exploitation is unlikely but still recommends prompt patching.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.