CVE-2026-97297: WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability
Published Oct 1, 2026
·Updated
Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
Affected Software
1 affected component
Gratisfaction Gratisfaction<=4.6.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Gratisfaction pluginto a version that resolves this vulnerability.Fixed in 4.6.4
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires subscriber-level privileges. It can be exploited remotely without user interaction, and the attack complexity is low.
2
What security impact could successful exploitation have?
Successful exploitation could expose highly sensitive information and allow limited modification or disruption of affected functionality. The listed vector indicates high confidentiality impact and low integrity and availability impact.
3
Which versions are affected?
Gratisfaction versions 4.6.3 and earlier are identified as affected.