CVE-2026-24638: WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerability
Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects RepairBuddy: from n/a through 4.1121.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/RepairBuddyto a version that resolves this vulnerability.Fixed in 4.1125
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24638?
The severity of CVE-2026-24638 is medium with a score of 4.3.
How do I fix CVE-2026-24638?
To fix CVE-2026-24638, you should update the WordPress RepairBuddy Plugin to at least version 4.1125.
What type of vulnerability is CVE-2026-24638?
CVE-2026-24638 is a Broken Access Control vulnerability.
Which versions of RepairBuddy are affected by CVE-2026-24638?
RepairBuddy versions from n/a up to and including 4.1121 are affected by CVE-2026-24638.
What could happen if CVE-2026-24638 is exploited?
If exploited, CVE-2026-24638 could allow unauthorized access to features due to incorrectly configured access controls.