CVE-2026-24590: WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Broken Access Control vulnerability
Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Paid Videochat Turnkey Site pluginto a version that resolves this vulnerability.Fixed in 7.3.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24590?
The severity of CVE-2026-24590 is medium with a score of 5.3.
How do I fix CVE-2026-24590?
To fix CVE-2026-24590, update the WordPress Paid Videochat Turnkey Site plugin to version 7.3.24 or later.
What is the nature of the vulnerability in CVE-2026-24590?
CVE-2026-24590 is a broken access control vulnerability allowing exploitation due to incorrectly configured access control security levels.
What versions of the Paid Videochat Turnkey Site are affected by CVE-2026-24590?
CVE-2026-24590 affects Paid Videochat Turnkey Site versions up to 7.3.23.
What impact does CVE-2026-24590 have on security?
The impact of CVE-2026-24590 can lead to unauthorized access due to inadequate authorization mechanisms.