PT-2026-31569 · Oliverfriedmann · Ziggeo
Nabil Irawan
·
Published
2026-04-09
·
Updated
2026-04-09
·
CVE-2026-4124
CVSS v3.1
5.4
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp ajax ziggeo ajax handler only verifies a nonce (check ajax referer) but performs no capability checks via current user can(). Furthermore, the nonce ('ziggeo ajax nonce') is exposed to all logged-in users on every page via the wp head and admin head hooks . This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke multiple administrative operations including: saving arbitrary translation strings (translations panel save strings via update option('ziggeo translations')), creating/updating/deleting event templates (event editor save template/update template/remove template via update option('ziggeo events')), modifying SDK application settings (sdk applications operations), and managing notifications (notification handler via update option('ziggeo notifications')).
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ziggeo