CVE-2026-27092: WordPress WPAdverts plugin <= 2.3.0 - Broken Access Control vulnerability
Published Feb 19, 2026
·Updated
Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.3.0.
Affected Software
1 affected component
Greg Winiarski WPAdverts<=2.3.0
Event History
Feb 19, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27092?
CVE-2026-27092 is classified as a Medium severity vulnerability due to its potential impact on access control.
2
How do I fix CVE-2026-27092?
To fix CVE-2026-27092, update the WPAdverts plugin to version 2.2.12 or later.
3
What impact does CVE-2026-27092 have on my WordPress site?
CVE-2026-27092 could allow unauthorized users to access restricted areas of your site due to misconfigured access control.
4
Which versions of WPAdverts are affected by CVE-2026-27092?
CVE-2026-27092 affects all versions of WPAdverts up to and including 2.2.11.
5
Is CVE-2026-27092 being actively exploited?
There is no current information indicating that CVE-2026-27092 is being actively exploited, but it poses a significant risk if left unpatched.