PT-2026-31569 · WordPress · Ziggeo

Nabil Irawan

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-4124

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ziggeo plugin for WordPress versions through 3.1.1
Description The Ziggeo plugin for WordPress is susceptible to missing authorization checks. The wp ajax ziggeo ajax handler verifies a nonce but does not confirm user capabilities using current user can(). The nonce (ziggeo ajax nonce) is publicly exposed to all logged-in users through the wp head and admin head hooks. This allows authenticated attackers with Subscriber-level access or higher to perform administrative actions, including saving arbitrary translation strings via the update option('ziggeo translations') function, creating, updating, and deleting event templates via update option('ziggeo events'), modifying SDK application settings, and managing notifications via update option('ziggeo notifications').
Recommendations Versions prior to 3.1.2 should be updated. As a temporary workaround, consider disabling the wp ajax ziggeo ajax handler until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4124

Affected Products

Ziggeo