AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66454

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

WP Social Avatar versions up to 1.5 are vulnerable to unauthenticated broken access control, allowing attackers to exploit this weakness to gain unauthorized access to sensitive functionalities or data. Organizations using this plugin should prioritize remediation to mitigate potential unauthorized access and protect user information.

CVE
CVE-2026-66454
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.