CVE-2026-81801: WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
Published Sep 10, 2026
·Updated
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Affected Software
1 affected component
wp-stateless<=4.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP-Stateless Pluginto a version that resolves this vulnerability.Fixed in 4.4.2
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Subscriber-level access. The vulnerability does not require user interaction and can be exploited over the network.
2
What is the potential impact if exploitation succeeds?
The issue can allow unauthorized settings changes, with high impact to integrity and availability. No confidentiality impact is indicated.