VYPR

RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

by RepairBuddy

CVEs (1)

  • CVE-2026-0820MedJan 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary signatures to any order in the system, potentially modifying order metadata and triggering unauthorized status changes.