Medium severity5.4NVD Advisory· Published Jul 10, 2026· Updated Jul 14, 2026
CVE-2026-58589
CVE-2026-58589
Description
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Affected products
3- Package: https://wordpress.org/plugins/drupal
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-067nvdVendor Advisory
News mentions
1- Drupal: Five Security Advisories Disclosed Together on July 1, 2026Vypr Intelligence · Jul 1, 2026