CVE-2026-39664
Description
Missing Authorization vulnerability in leadrebel Leadrebel leadrebel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadrebel: from n/a through <= 1.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Leadrebel WordPress plugin <=1.0.2 has a missing authorization vulnerability allowing attackers to exploit broken access control.
Vulnerability
Overview The Leadrebel WordPress plugin, version 1.0.2 and earlier, suffers from a missing authorization vulnerability. This issue stems from incorrectly configured access control security levels, which fail to properly validate user permissions for certain functions or endpoints [1].
Exploitation
Method An attacker can exploit this vulnerability without authentication, as there is no nonce or capability check. By sending crafted requests, they can trigger privileged actions that should be restricted to higher-level users. The attack surface is exposed through the plugin's REST API or admin-ajax hooks, making it possible to target any WordPress site running the vulnerable version [1].
Impact
Successful exploitation allows an attacker to perform unauthorized actions, such as modifying site settings, accessing sensitive data, or escalating privileges. This can lead to complete site compromise if combined with other vulnerabilities. The plugin is often used in mass-exploit campaigns due to the low complexity of exploitation [1].
Mitigation
The vendor has not released a patch; users should update the plugin to the latest available version or remove it if no update is provided. As immediate action, deactivate the plugin and consult with a web developer to implement additional access controls. The vulnerability is tracked on Patchstack and may be added to CISA's KEV list [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.