CVE-2026-103752: WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Affected Software
1 affected component
WordPress Authorizer<=3.15.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Authorizer pluginto a version that resolves this vulnerability.Fixed in 3.16.0
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in privilege escalation. The assigned critical severity vector indicates potential high impact to confidentiality, integrity, and availability.
3
Which installations are affected?
WordPress sites using the Authorizer plugin version 3.15.3 or earlier are affected according to the available data.