CVE-2026-48199: WordPress Sermon'e plugin <= 1.0.2 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
Affected Software
1 affected component
WordPress Sermon'e plugin<=1.0.2
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or existing privileges to exploit it. The network attack vector and low attack complexity indicate it can be targeted remotely with minimal prerequisites.
2
What is the potential impact if exploitation succeeds?
The reported impact is high confidentiality impact. Integrity and availability impacts are listed as none, so the provided data indicates exposure of information rather than modification or disruption.
3
Which installations are affected?
WordPress sites using the Sermon'e plugin version 1.0.2 or earlier are affected according to the advisory data.