CVE-2026-78528: WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
Affected Software
1 affected component
WordPress BerqWP plugin<=4.1.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BerqWP pluginto a version that resolves this vulnerability.Fixed in 4.1.16
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
What security impact is identified?
The reported impact is integrity loss only. The provided severity vector indicates no confidentiality or availability impact.
3
Which deployments are affected?
BerqWP plugin versions 4.1.15 and earlier are identified as affected. The provided information does not state whether a particular configuration is required.