CVE-2026-0820: RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wcuploadandsavesignaturehandler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary signatures to any order in the system, potentially modifying order metadata and triggering unauthorized status changes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0820?
CVE-2026-0820 is considered a high severity vulnerability due to its potential for arbitrary signature uploads.
How do I fix CVE-2026-0820?
To fix CVE-2026-0820, you should update the RepairBuddy plugin to a version newer than 4.1116 that includes proper capability checks.
Who is affected by CVE-2026-0820?
Users of the RepairBuddy plugin for WordPress version 4.1116 and below are affected by CVE-2026-0820.
What type of vulnerability is CVE-2026-0820?
CVE-2026-0820 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What are the potential impacts of CVE-2026-0820?
The potential impacts of CVE-2026-0820 include unauthorized access to upload arbitrary signatures to orders, which can compromise the integrity of the system.