CVE-2026-73394: WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Affected Software
1 affected component
WordPress Stitch Express plugin<=1.9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Stitch Express pluginto a version that resolves this vulnerability.Fixed in 1.9.0
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any existing privileges to exploit it.
2
Which installations are affected?
WordPress sites using the Stitch Express plugin version 1.9.0 or earlier are affected. The provided information does not identify any configuration prerequisite.
3
What is the likely security impact?
The vulnerability is rated high with a CVSS score of 7.5 and impacts integrity. The provided data does not indicate confidentiality or availability impact.