PT-2026-8084 · WordPress · Callbackkiller Service Widget

Abhirup Konwar

·

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2026-1944

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CallbackKiller service widget plugin for WordPress versions prior to 1.3
Description The CallbackKiller service widget plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check within the cbk save() function. An unauthenticated attacker can exploit this to modify the plugin’s site ID settings through the 'cbk save v1' API Endpoint.
Recommendations Update the CallbackKiller service widget plugin to version 1.3 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1944

Affected Products

Callbackkiller Service Widget