What is CVE-2026-73385?
CVE-2026-73385 is an unauthenticated Broken Access Control vulnerability in Outranking plugin versions <= 1.1.3. It may allow attackers to modify plugin options without authorization. It is recommended to temporarily disable the plugin until a patch is released.
Azərbaycanca: CVE-2026-73385, Outranking plaginin 1.1.3 və daha əvvəlki versiyalarında autentifikasiya olunmadan "Broken Access Control" zəifliyidir. Bu, təcavüzkara plagin seçimlərini icazəsiz dəyişməyə imkan verə bilər. Plagin yeniləməsi buraxılana qədər onu müvəqqəti deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Outranking plugin are affected by CVE-2026-73385?
Outranking plugin versions 1.1.3 and earlier are affected by CVE-2026-73385.
What temporary measure is recommended for users upon discovery of CVE-2026-73385?
It is recommended to temporarily disable the Outranking plugin until a patch is released.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.