CVE-2026-81294: WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Affected Software
1 affected component
WordPress Authorizer plugin<=3.15.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Authorizer pluginto a version that resolves this vulnerability.Fixed in 3.15.2
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is unauthenticated, so no WordPress account or prior privileges are required according to the available information.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in privilege escalation. The supplied severity vector rates confidentiality, integrity, and availability impact as high.
3
Which plugin versions are known to be affected?
Authorizer versions 3.15.1 and earlier are identified as affected.