VYPR
Medium severity5.3NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-24997

CVE-2026-24997

Description

Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Wired Impact Volunteer Management plugin ≤2.8 allows unprivileged users to access higher-privileged functions.

The Wired Impact Volunteer Management plugin for WordPress versions up to and including 2.8 contains a broken access control vulnerability due to missing authorization checks. This issue stems from incorrectly configured access control security levels, allowing exploitation of missing authorization in certain plugin functions [1].

To exploit this vulnerability, an attacker does not need elevated privileges; unauthenticated or low-privileged users can leverage the missing authorization checks to perform actions that should require higher-level permissions. The attack vector is network-based, requiring no special access or user interaction beyond sending crafted requests to the affected WordPress site [1].

The impact of successful exploitation includes unauthorized access to plugin functionality, potentially leading to privilege escalation or data manipulation. While the CVSS score of 5.3 indicates medium severity, the vulnerability is noted to be part of mass-exploit campaigns targeting thousands of sites, regardless of their size or popularity [1].

Mitigation is available by updating the plugin to version 2.8.1 or later, which addresses the missing authorization. Users are advised to immediately apply the patch or enable auto-updates if using Patchstack. For those unable to update, consulting the hosting provider or developer is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.