CVE-2026-97243: WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
Affected Software
1 affected component
AllAble AllAble Connector<=0.13.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AllAble Connector Pluginto a version that resolves this vulnerability.Fixed in 0.13.6
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users could exploit this issue?
The vulnerability is described as subscriber broken access control, so it affects sites where a user can authenticate with the Subscriber role.
2
Does exploitation require an authenticated account?
Yes. The vector lists privileges required as low, indicating an attacker needs a low-privileged account rather than unauthenticated access.
3
What is the potential impact?
The supplied severity vector indicates low impact to confidentiality and integrity, with no availability impact.