CVE-2026-66708: WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
Published Aug 6, 2026
·Updated
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Affected Software
1 affected component
WordPress Total Upkeep plugin<=1.17.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Total Upkeep Pluginto a version that resolves this vulnerability.Fixed in 1.17.3
Event History
Aug 6, 2026
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66708?
The severity of CVE-2026-66708 is rated as high with a score of 8.2.
2
How do I fix CVE-2026-66708?
To address CVE-2026-66708, update the WordPress Total Upkeep plugin to the latest version above 1.17.2.
3
What type of vulnerability is CVE-2026-66708?
CVE-2026-66708 is classified as an Unauthenticated Broken Access Control vulnerability.
4
What versions are affected by CVE-2026-66708?
CVE-2026-66708 affects WordPress Total Upkeep plugin versions 1.17.2 and below.
5
Does CVE-2026-66708 involve user authentication?
CVE-2026-66708 does not require user authentication to exploit the vulnerability.