What is CVE-2026-16546?
CVE-2026-16546 is a vulnerability in the Wired Impact Volunteer Management WordPress plugin before version 2.8.2. Due to missing authorization checks in an AJAX action and a lack of verification that the RSVP belongs to the requesting user, even low-privileged users like Subscribers can delete arbitrary users' RSVPs. Updating the plugin to version 2.8.2 or later is strongly recommended.
Azərbaycanca: CVE-2026-16546, Wired Impact Volunteer Management WordPress plaginində 2.8.2 versiyasından əvvəl aşkar edilmiş zəiflikdir. AJAX əməliyyatlarında avtorizasiya yoxlanışının olmaması səbəbindən Subscriber kimi aşağı səviyyəli istifadəçilər istənilən istifadəçinin RSVP qeydlərini silə bilər. Təsirə məruz qalmamaq üçün plagini dərhal 2.8.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and versions are affected by CVE-2026-16546?
This vulnerability affects all versions of the Wired Impact Volunteer Management WordPress plugin prior to version 2.8.2.
What can a Subscriber-level user do by exploiting CVE-2026-16546?
CVE-2026-16546 allows a low-privileged user like a Subscriber to delete any user's RSVP records due to missing authorization checks in an AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.