What is CVE-2026-11907?
The Stream plugin for WordPress up to version 4.2.0 is vulnerable to an authorization bypass, allowing authenticated attackers with Subscriber-level access to perform unauthorized actions. Users should update to the latest patched version immediately.
Azərbaycanca: Stream plaqini (WordPress) 4.2.0 və əvvəlki versiyalarında Subscriber səviyyəli istifadəçilərin icazəsiz əməliyyatlar aparmasına imkan verən authorization bypass zəifliyi aşkar edilib. Sayt sahibləri dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WordPress Stream plugin are affected by CVE-2026-11907?
This authorization bypass vulnerability affects the Stream plugin versions 4.2.0 and earlier.
What access level does an attacker need to exploit CVE-2026-11907?
An attacker needs to have authenticated access with Subscriber-level permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.