VYPR
Medium severity5.3NVD Advisory· Published Apr 8, 2026· Updated Apr 29, 2026

CVE-2026-39706

CVE-2026-39706

Description

Missing Authorization vulnerability in Netro Systems Make My Trivia trivialy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Make My Trivia: from n/a through <= 1.1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing Authorization in Make My Trivia WordPress plugin (<=1.1.0) allows unauthenticated access to higher-privileged actions.

Vulnerability

Overview

The Make My Trivia plugin for WordPress, up to and including version 1.1.0, contains a Missing Authorization vulnerability. This is a type of Broken Access Control issue where the plugin fails to properly verify nonce tokens or user capabilities before executing privileged functions [1].

Attack

Vector

An unauthenticated attacker can exploit this by sending crafted requests to the plugin's endpoints that lack proper authorization checks. The vulnerability does not require any previous authentication or special network position [1]. This makes it trivially exploitable in mass-exploit campaigns targeting thousands of websites simultaneously [1].

Impact

Successful exploitation allows an attacker to perform actions intended only for higher-privileged users, potentially including creating, modifying, or deleting arbitrary content or configuration settings. The CVSS score of 5.3 reflects the medium severity due to the low complexity and network attack vector [1].

Mitigation

The plugin vendor has not released a patched version. Users are strongly advised to update to version 1. If no update is available, the plugin should be removed or access restricted via web application firewall rules. Immediate action is recommended as these vulnerabilities are actively targeted in mass campaigns [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.