What is CVE-2026-10782?
CVE-2026-10782 is a critical authorization bypass vulnerability in the RealHomes Memberships plugin for WordPress, affecting all versions up to and including 3.0.9. This flaw allows authenticated attackers with subscriber-level access to perform unauthorized actions due to improper verification of user capabilities. Users are advised to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-10782, WordPress-in RealHomes Memberships plaginində 3.0.9 daxil olmaqla bütün versiyalarda mövcud olan kritik authorization bypass zəifliyidir. Bu boşluq vasitəsilə subscriber səviyyəli autentifikasiya olunmuş hücumçular səlahiyyətləri olmayan əməliyyatları icra edə bilərlər. İstifadəçilərə plaginini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What level of authentication does an attacker need to exploit CVE-2026-10782?
To exploit this vulnerability, an attacker must be an authenticated user with subscriber-level access.
What software product is affected by CVE-2026-10782?
This vulnerability affects the RealHomes Memberships plugin for WordPress in all versions up to and including 3.0.9.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.