CVE-2026-81788: WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability
Published Sep 10, 2026
·Updated
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
Affected Software
1 affected component
WordPress IMPress for IDX Broker<=3.3.0
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with Subscriber-level access can exploit the broken access control issue. The vulnerability is remotely reachable and does not require user interaction.
2
Which installations are affected?
IMPress for IDX Broker versions up to and including 3.3.0 are affected. The provided information does not identify any configuration prerequisite.
3
What impact could exploitation have?
The supplied CVSS vector indicates low impact to confidentiality, integrity, and availability. Exploitation requires low privileges and has low attack complexity.