← WordPress Vulnerabilities
WordPress security by component

Builderall for WordPress

Builderall for WordPress is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: builderall-for

CVE-2026-11882: Builderall OAuth state is not bound to the initiating visitor

Builderall for WordPress before 3.0.2 exposes public OAuth routes whose state value is not bound to the browser session that initiated authorization. An unauthenticated attacker can complete a connection flow and replace the access token stored for the site's third-party integration; a durable overwrite requires the site to already be connected to a paid account. The published record does not disclose the routes, state and code parameters, callback function or provider scopes available to the replacement token.

PublishedAug 01, 2026
Known safe version3.0.2
Safe version
Aug 01, 2026 CVE-2026-11882
Builderall OAuth state is not bound to the initiating visitor
Builderall for WordPress before 3.0.2 exposes public OAuth routes whose state value is not bound to the browser session that initiated authorization. An unauthenticated attacker can complete a connection flow and replace the access token stored for the site's third-party integration; a durable overwrite requires the site to already be connected to a paid account. The published record does not disclose the routes, state and code parameters, callback function or provider scopes available to the replacement token.
3.0.2
CVEPending
NVDPending