VYPR
Medium severity5.4NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32416

CVE-2026-32416

Description

Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Poster: from n/a through <= 2.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in PDF Poster plugin ≤2.4.0 allows unauthenticated attackers to exploit broken access controls, potentially compromising WordPress sites.

Vulnerability

Overview

The PDF Poster plugin for WordPress, versions 2.4.0 and earlier, contains a missing authorization vulnerability [1]. This broken access control issue stems from the plugin's failure to properly verify user permissions or nonce tokens in certain functions, allowing unauthenticated or low-privileged users to execute actions that should require higher privileges [1].

Exploitation

Attackers can exploit this vulnerability remotely without authentication, as the plugin does not enforce proper access control checks [1]. The attack surface is broad because the plugin is widely used, and the vulnerability can be chained with other techniques to target thousands of sites in mass-exploit campaigns [1]. No special network position or user interaction is required beyond visiting a crafted URL or sending a malicious request.

Impact

Successful exploitation allows an attacker to perform unauthorized access to protected functionality, such as modifying plugin settings, accessing sensitive data, or performing other privileged actions [1]. The CVSS v3 score of 5.4 (Medium) reflects the potential for partial compromise of confidentiality and integrity, though the overall impact is limited compared to critical vulnerabilities [1].

Mitigation

The vendor has released version 2.4.1, which patches the missing authorization issue [1]. Users are strongly advised to update immediately. For those unable to update, contacting a hosting provider or web developer for assistance is recommended [1]. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.