CVE-2026-40777: WordPress WPSection plugin <= 1.5.1 - Broken Access Control vulnerability
Published Oct 10, 2026
·Updated
Subscriber Broken Access Control in WPSection <= 1.5.1 versions.
Affected Software
1 affected component
WordPress WPSection<=1.5.1
Event History
Oct 10, 2026
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated WordPress user with the Subscriber role can exploit the broken access control issue. No user interaction is required.
2
What is the potential impact?
The vulnerability can affect integrity and availability, with no confidentiality impact indicated by the supplied vector. It is remotely reachable and has low attack complexity.
3
Which plugin versions are affected?
WPSection versions up to and including 1.5.1 are affected.