CVE-2026-18364: Zportals < 6.4.2 - Subscriber+ Arbitrary Plugin Settings Update
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integration settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
zportals WordPress pluginto a version that resolves this vulnerability.Fixed in 6.4.2
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with a subscriber-level account can exploit the affected AJAX actions. No higher-privileged WordPress role is required.
What conditions are required for exploitation?
The attacker needs a subscriber account on a site running a zportals WordPress plugin version earlier than 6.4.2. The issue affects AJAX actions that lack both capability and nonce checks.
What can an attacker change?
An attacker can modify stored integration settings in the zportals plugin.
Are installations running version 6.4.2 affected?
No. The issue is described as affecting versions before 6.4.2.