CVE-2026-40737: WordPress COMPE plugin <= 1.1.4 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects COMPE: from n/a through <= 1.1.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40737?
CVE-2026-40737 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2026-40737?
To fix CVE-2026-40737, update the VillaTheme COMPE compe-woo-compare-products plugin to version 1.1.5 or later.
What does CVE-2026-40737 exploit in the COMPE plugin?
CVE-2026-40737 exploits incorrectly configured access control settings, allowing an authorization bypass through user-controlled keys.
Who is affected by CVE-2026-40737?
CVE-2026-40737 affects users of the VillaTheme COMPE compe-woo-compare-products plugin version 1.1.4 and earlier.
Is CVE-2026-40737 easy to exploit?
Yes, CVE-2026-40737 can be easily exploited by attackers familiar with the plugin's structure and the underlying access control issues.