What is CVE-2026-27392?
CVE-2026-27392 is a Contributor Broken Access Control vulnerability found in uListing plugin versions 2.2.0 and earlier. It allows users with contributor role to perform unauthorized actions beyond their intended permissions. Updating to the latest patched version is strongly recommended to mitigate the risk.
Azərbaycanca: CVE-2026-27392 zəifliyi uListing plaginin 2.2.0 və daha əvvəlki versiyalarında aşkarlanmış Contributor Broken Access Control problemidir. Bu, contributor roluna malik istifadəçilərin səlahiyyətlərini aşaraq icazəsiz əməliyyatlar aparmasına imkan verir. Təhlükəsizlik üçün plaginin ən son, patched versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which plugin is affected by CVE-2026-27392?
CVE-2026-27392 affects the uListing plugin versions 2.2.0 and earlier.
What role level does an attacker need to exploit this vulnerability?
An attacker needs to have a contributor role to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.