CVE-2026-59522: WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability
Published Jul 23, 2026
·Updated
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Affected Software
1 affected component
WP ERP<=1.17.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP ERP Pluginto a version that resolves this vulnerability.Fixed in 1.17.6
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59522?
The severity of CVE-2026-59522 is medium with a score of 6.5.
2
What does CVE-2026-59522 exploit?
CVE-2026-59522 exploits Broken Access Control vulnerabilities in the WP ERP plugin versions up to 1.17.5.
3
How do I fix CVE-2026-59522?
To fix CVE-2026-59522, update the WP ERP plugin to version 1.17.6 or later.
4
What are the impacts of CVE-2026-59522?
The impact of CVE-2026-59522 allows unauthorized access to subscriber-level functionalities.
5
Who is affected by CVE-2026-59522?
Users of the WP ERP plugin versions 1.17.5 and earlier are affected by CVE-2026-59522.