WordPress security by component
Builderall for WordPress
Plugin description
Builderall for WordPress is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
builderall-forLatest vulnerability
CVE-2026-11882: Builderall OAuth state is not bound to the initiating visitor
Builderall for WordPress before 3.0.2 exposes public OAuth routes whose state value is not bound to the browser session that initiated authorization. An unauthenticated attacker can complete a connection flow and replace the access token stored for the site's third-party integration; a durable overwrite requires the site to already be connected to a paid account. The published record does not disclose the routes, state and code parameters, callback function or provider scopes available to the replacement token.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-11882
Builderall OAuth state is not bound to the initiating visitor
Builderall for WordPress before 3.0.2 exposes public OAuth routes whose state value is not bound to the browser session that initiated authorization. An unauthenticated attacker can complete a connection flow and replace the access token stored for the site's third-party integration; a durable overwrite requires the site to already be connected to a paid account. The published record does not disclose the routes, state and code parameters, callback function or provider scopes available to the replacement token.
|
3.0.2 |
CVEPending
NVDPending
|