CVE-2026-62028: WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Broken Access Control vulnerability
Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. It is remotely exploitable and does not require user interaction.
Which plugin versions are affected?
Before After Image Comparison – Image comparison for WP is affected through version 1.1.21. The available data does not identify a fixed version.
What is the likely impact if exploited?
The stated CVSS vector indicates low-impact confidentiality and integrity effects, with no availability impact. The issue is categorized as broken access control caused by missing authorization.