CVE-2026-66455: WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
Affected Software
1 affected component
ReactPress<=3.4.0
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66455?
The severity of CVE-2026-66455 is classified as medium with a score of 6.
2
How do I fix CVE-2026-66455?
To mitigate CVE-2026-66455, update the ReactPress plugin to version 3.4.1 or higher.
3
What type of vulnerability is CVE-2026-66455?
CVE-2026-66455 is a Broken Access Control vulnerability affecting the ReactPress WordPress plugin.
4
Who is affected by CVE-2026-66455?
Subscribers using ReactPress plugin versions 3.4.0 and below are affected by CVE-2026-66455.
5
What are the potential impacts of CVE-2026-66455?
CVE-2026-66455 can lead to unauthorized access and manipulation of content by subscribers.