CVE-2026-85681
The WP Component WordPress plugin up to version 2.2.4 allows unauthenticated users to overwrite any site option because it lacks capability or nonce checks. This can lead to a full site takeover, including enabling registration with administrator privileges. The vulnerability is critical with a CVSS score of 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites using the WP Component WordPress plugin version 2.2.4 or earlier.
Real-world impact
An attacker can change any site setting, including enabling user registration and granting themselves administrator rights, effectively taking full control of the site.
Why this severity
The CVSS score is high because the vulnerability is network accessible, requires no authentication, and gives complete control over the site, affecting confidentiality, integrity, and availability.
What to do about it
- ›Disable or remove the WP Component WordPress plugin until a patch is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.