VYPR
Medium severity5.3NVD Advisory· Published Apr 8, 2026· Updated Apr 24, 2026

CVE-2026-39685

CVE-2026-39685

Description

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Moneytizer WordPress plugin <=10.0.10 has a missing authorization vulnerability allowing unauthenticated privilege escalation.

Vulnerability

Overview The Moneytizer WordPress plugin versions up to and including 10.0.10 contain a missing authorization vulnerability. This broken access control issue stems from incorrectly configured access control security levels, meaning the plugin fails to properly verify user permissions before allowing certain actions [1].

Exploitation

Exploitation

Attackers can exploit this vulnerability without authentication, as the missing authorization check allows any unauthenticated user to access higher-privileged functions. This type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity [1].

Impact

Successful exploitation enables an attacker to perform actions that should be restricted to higher-privileged users, potentially leading to site compromise, data exposure, or further attacks. The CVSS v3 base score of 5.3 (Medium) reflects the moderate severity of this broken access control issue [1].

Mitigation

The vendor has not released a patched version beyond 10.0.10 at the time of publication. Users are strongly advised to update the plugin immediately if a fix becomes available. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.