CVE-2026-66677: WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability
Published Aug 20, 2026
·Updated
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Affected Software
1 affected component
wordpress/leyka<=3.32.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Leyka pluginto a version that resolves this vulnerability.Fixed in 3.32.3
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires subscriber-level privileges. It does not require user interaction and can be exploited over the network.
2
Which Leyka installations are affected?
Leyka versions up to and including 3.32.3 are affected. The available data does not identify a fixed version or any configuration-dependent limitation.