What is CVE-2026-4604?
The Klubraum Membership Request plugin for WordPress (versions up to 1.1.0) lacks a capability check in the `kr_mr_store_settings()` function, allowing unauthenticated attackers to modify plugin settings without authorization. Users should update to the latest version or temporarily disable the plugin.
Azərbaycanca: Klubraum Membership Request plugininin 1.1.0-a qədər versiyalarında `kr_mr_store_settings()` funksiyasında çatışmayan icazə yoxlaması səbəbindən autentifikasiya olunmamış hücumçular plagin parametrlərini icazəsiz dəyişdirə bilərlər. WordPress istifadəçiləri plaqini dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Klubraum Membership Request plugin are affected by the unauthorized settings modification vulnerability?
This vulnerability affects all versions of the plugin up to 1.1.0.
What does this vulnerability allow an unauthenticated attacker to do?
Due to a missing capability check in the `kr_mr_store_settings()` function, unauthenticated attackers can modify the plugin settings without authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.