What is CVE-2026-11882?
A critical vulnerability in Builderall for WordPress plugin versions before 3.0.2. The issue arises from the public OAuth authentication routes not binding the "state" value to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite stored third-party integration access tokens. Updating the plugin to the latest version is recommended.
Azərbaycanca: Builderall for WordPress plaqininin 3.0.2-dən əvvəlki versiyalarında aşkar edilmiş kritik boşluqdur. OAuth autentifikasiya rutalarında "state" parametrinin istifadəçi sessiyasına bağlanmaması səbəbindən, autentifikasiya olunmamış hücumçular bu axını tamamlayaraq saxlanılan üçüncü tərəf inteqrasiya giriş tokenini dəyişdirə bilər. Plaqinin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Why is the CVE-2026-11882 vulnerability considered critical in the Builderall for WordPress plugin?
The vulnerability is critical because it allows unauthenticated attackers to overwrite stored third-party integration access tokens.
What should be done to protect against the CVE-2026-11882 vulnerability?
Updating the plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.