CVE-2026-85681: WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update

Published Sep 12, 2026
·
Updated

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.

Affected Software

0 affected components

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WP Component WordPress plugin to a version that resolves this vulnerability.

    Fixed in 2.2.4

Event History

Sep 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are explicitly known to be at risk of full site takeover?

Single-site WordPress installations using the affected plugin are explicitly described as susceptible to full takeover. The attack can enable registration and set the default role to administrator.

2

Does exploitation require an authenticated WordPress account or user interaction?

No. The affected action is available to unauthenticated users and lacks both capability and nonce checks.

3

What is the immediate risk if the plugin cannot be updated yet?

An unauthenticated attacker can overwrite arbitrary site options through the vulnerable action. On a single-site installation, this can be used to enable registration and create an administrator-level account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203