CVE-2026-97258: WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
Published Oct 1, 2026
·Updated
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Affected Software
1 affected component
Aruba Aruba Migration Tool<=1.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Aruba Migration Tool pluginto a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated WordPress user with Subscriber-level access can exploit the broken access control condition.
2
Does exploitation require user interaction or complex attack conditions?
No. The available vector indicates network-reachable exploitation with low attack complexity and no user interaction required.
3
What is the potential impact?
The issue may expose confidential information. The provided scoring indicates no integrity or availability impact.