CVE-2026-24566: WordPress iNET Webkit plugin <= 1.2.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iNET Webkit: from n/a through <= 1.2.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24566?
CVE-2026-24566 has been rated as a medium severity vulnerability due to its potential impact on user access control.
How do I fix CVE-2026-24566?
To fix CVE-2026-24566, update the iNET Webkit plugin to version 1.2.5 or later to ensure proper access controls are implemented.
What is the impact of CVE-2026-24566?
The impact of CVE-2026-24566 allows unauthorized users to exploit incorrectly configured access control levels, potentially compromising sensitive information.
Which versions are affected by CVE-2026-24566?
CVE-2026-24566 affects iNET Webkit versions up to and including 1.2.4.
Who is vulnerable to CVE-2026-24566?
Any WordPress site using the iNET Webkit plugin version 1.2.4 or earlier is vulnerable to CVE-2026-24566.