CVE-2026-24520: WordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerability
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Tiktok Feed: from n/a through 1.0.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tiktok Feed pluginto a version that resolves this vulnerability.Fixed in 1.0.25
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24520?
CVE-2026-24520 has a medium severity rating of 4.3.
How do I fix CVE-2026-24520?
To fix CVE-2026-24520, update the WordPress Tiktok Feed Plugin to version 1.0.25 or later.
What is the main issue of CVE-2026-24520?
CVE-2026-24520 is a Broken Access Control vulnerability due to missing authorization in bPlugins Tiktok Feed.
Which versions of the Tiktok Feed plugin are affected by CVE-2026-24520?
CVE-2026-24520 affects bPlugins Tiktok Feed versions up to and including 1.0.24.
What kind of threat does CVE-2026-24520 pose?
CVE-2026-24520 allows attackers to exploit incorrectly configured access control security levels.