CVE-2026-28190: WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerability
Published Aug 24, 2026
·Updated
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Affected Software
1 affected component
WordPress ProLancer Element plugin<=1.4.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ProLancer Element pluginto a version that resolves this vulnerability.Fixed in 1.4.8
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs a low-privileged account, specifically Subscriber-level access. The issue is reachable over the network and does not require user interaction.
2
What is the potential impact of successful exploitation?
The vulnerability has high integrity impact and low availability impact. No confidentiality impact is indicated by the provided CVSS vector.
3
Which installations are affected?
ProLancer Element plugin versions 1.4.8 and earlier are identified as affected.