PT-2026-50633 · WordPress · Accessibility Checker By Equalize Digital
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Equalize Digital Accessibility Checker versions prior to 1.42.2
Description
The plugin fails to properly verify user authorization when performing actions on accessibility audit issue records. Authenticated users with author-level access or higher can dismiss, ignore, or restore records belonging to posts they are not permitted to edit. This is achieved by providing an issue from their own post as an authorization token to affect matching issues across the entire site. Specifically, an attacker can use the
largeBatch=true parameter in a 'dismiss-issue' request to bulk-modify all site-wide accessibility issues that share the same object value, including those associated with administrator-owned posts.Recommendations
Update the plugin to a version later than 1.42.1.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accessibility Checker By Equalize Digital