CVE-2026-97309: WordPress RepairBuddy plugin <= 4.1226 - Sensitive Data Exposure vulnerability
Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RepairBuddy pluginto a version that resolves this vulnerability.Fixed in 4.1227
Event History
Frequently Asked Questions
What deployments are affected?
RepairBuddy installations are affected through version 4.1226. The available data does not identify a fixed version.
What access does an attacker need to exploit this issue?
The issue is described as missing authorization, but the available data does not specify whether an attacker must be authenticated or which permissions, if any, are required.
What information could be exposed?
The vulnerability allows retrieval of embedded sensitive data. The available data does not identify the specific data types or affected application components.