What is CVE-2026-27423?
CVE-2026-27423 is a 'Subscriber Broken Access Control' vulnerability found in the 'Participants Database' plugin up to version 2.7.8.4. This flaw could allow low-privileged 'Subscriber' users to gain unauthorized access. It is recommended to update the plugin to the latest version.
Azərbaycanca: CVE-2026-27423 'Participants Database' plaqinində (versiya 2.7.8.4-dək) aşkarlanmış 'Subscriber Broken Access Control' zəifliyidir. Bu boşluq aşağı səviyyəli 'Subscriber' istifadəçilərinə icazəsiz giriş imkanı yarada bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How to protect the plugin affected by CVE-2026-27423?
It is recommended to update the ‘Participants Database’ plugin to the latest version.
Which user role could gain unauthorized access through CVE-2026-27423?
This 'Subscriber Broken Access Control' vulnerability could allow low-privileged 'Subscriber' users to gain unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.