CVE-2026-81758: WordPress OwnerRez API plugin <= 1.2.6 - Broken Access Control vulnerability
Published Aug 31, 2026
·Updated
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
Affected Software
1 affected component
WordPress OwnerRez API plugin<=1.2.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OwnerRez API pluginto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated WordPress user with Subscriber-level access can exploit the broken access control issue. No user interaction is required.
2
What is the potential impact?
Successful exploitation can affect the confidentiality, integrity, and availability of the affected system at a low level, as reflected by the CVSS vector.
3
Which plugin versions are affected?
OwnerRez API plugin versions up to and including 1.2.6 are affected.