CyberRota
← Ana sayfaya dön

CVE-2026-8682

MEDIUM · CVSS 4.3 EPSS %0.23

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-28T08:16:37.590 · Çekilme zamanı: 2026-06-27T06:04:38.902809+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-8682
Severity
MEDIUM
CVSS
4.3
EPSS
%0.23
WordPress

Orijinal NVD Açıklaması

The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify all plugin settings by writing arbitrary data to the ar_try_on_settings option in the database via the /wp-json/ar_try_on/v1/settings REST endpoint.