OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86707

CRITICAL · CVSS 9.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Private Feed Key WordPress plugin versions up to 0.1 are vulnerable due to a lack of proper authentication verification for feed request keys, allowing unauthenticated attackers to impersonate any user, including those with administrative privileges. This vulnerability poses a significant risk of unauthorized access and potential exploitation of sensitive data within WordPress sites. WordPress site administrators and security teams should prioritize addressing this issue to mitigate the risk of account takeover and data breaches.

CVE
CVE-2026-86707
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%
WordPress

Original NVD Description

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.