CVE-2026-27416
Description
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects PDF Poster: from n/a through 2.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in PDF Poster plugin (≤2.4.1) allows unprivileged users to execute higher privileged actions, enabling mass exploitation.
The PDF Poster plugin for WordPress (versions through 2.4.1) contains a missing authorization vulnerability. The plugin fails to properly check user capabilities or nonce tokens in certain functions, allowing unauthenticated or low-privileged users to access and execute actions intended for higher-privileged roles [1].
Attackers can exploit this flaw without any authentication, as the access control checks are incorrectly configured. This vulnerability is actively used in mass-exploit campaigns targeting thousands of WordPress sites, regardless of their size or traffic [1].
Successful exploitation allows an attacker to perform unauthorized actions, such as modifying plugin settings or accessing sensitive data, depending on the missing authorization context. The CVSS v3 base score is 5.3 (Medium), reflecting the potential for unauthorized access without complex prerequisites [1].
The vendor has released version 2.5.0, which addresses the issue. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. Although the vendor rates the impact as low and exploitation unlikely, the active use in mass campaigns warrants prompt patching [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=2.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (May 4, 2026 to May 10, 2026)Wordfence Blog · May 14, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 27, 2026 to May 3, 2026)Wordfence Blog · May 7, 2026