What is CVE-2026-27391?
CVE-2026-27391 is a 'Subscriber Broken Access Control' vulnerability found in uListing <= 2.2.0 versions. This flaw may allow users with a low-privileged 'Subscriber' role to gain unauthorized access to restricted functionalities. Users of uListing should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-27391, uListing plagininin 2.2.0 və daha əvvəlki versiyalarında aşkarlanmış 'Subscriber Broken Access Control' zəifliyidir. Bu zəiflik aşağı səlahiyyətli 'Subscriber' roluna malik istifadəçilərə normalda əllərində olmayan funksiyalara giriş imkanı verə bilər. uListing istifadəçiləri dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of uListing are affected by CVE-2026-27391?
uListing plugin versions 2.2.0 and earlier are affected by this vulnerability.
Which privilege level of user can perform unauthorized actions by exploiting CVE-2026-27391?
A user with the low-privileged 'Subscriber' role can gain unauthorized access to restricted functionalities that are normally inaccessible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.