CVE-2026-73994: WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Charitable pluginto a version that resolves this vulnerability.Fixed in 1.8.12
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites using the WordPress Charitable plugin at version 1.8.11.3 or earlier are affected according to the available data. The issue is reachable over the network without authentication or user interaction.
What does an attacker need to exploit this issue?
An attacker does not need an account, prior privileges, or user interaction. The low attack complexity indicates exploitation does not require unusual conditions.
What can be done while a vendor fix or mitigation is unavailable?
The available data does not identify a fixed version, workaround, mitigation, or detection method. Until that information is available, organizations should identify installations of Charitable 1.8.11.3 or earlier and treat them as potentially exposed.