← WordPress Vulnerabilities
WordPress security by component

RepairBuddy

RepairBuddy (computer-repair-shop) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Sep 10, 2026; the highest published CVSS base score is 10.

Plugin slug: computer-repair-shop

CVE-2026-81803: RepairBuddy permits subscriber-level remote code execution

RepairBuddy through 4.1224 has a code-injection flaw that permits remote code execution by an authenticated Subscriber. The CNA rates attack complexity as high and identifies high confidentiality, integrity, and availability impact without requiring another user's interaction.

PublishedSep 10, 2026
Known safe version4.1225
Published vulnerabilities for computer-repair-shop
Safe version
Sep 10, 2026 CVE-2026-81803
RepairBuddy permits subscriber-level remote code execution
RepairBuddy through 4.1224 has a code-injection flaw that permits remote code execution by an authenticated Subscriber. The CNA rates attack complexity as high and identifies high confidentiality, integrity, and availability impact without requiring another user's interaction.
4.1225
CVE7.5
NVDPending
Aug 24, 2026 CVE-2026-78291
RepairBuddy exposes a state-changing operation without authentication
RepairBuddy through 4.1223 exposes an operation without the authorization it requires. An unauthenticated requester can alter protected state, producing low integrity impact.
4.1224
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-39584
RepairBuddy: Broken access control
RepairBuddy is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.1132.
4.1133
CVE6.5
NVDPending
May 26, 2026 CVE-2026-24638
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.1121.
4.1125
CVE4.3
NVDPending
Apr 08, 2026 CVE-2026-39586
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.1132.
4.1133
CVE5.3
NVDPending
Mar 21, 2026 CVE-2026-3567
RepairBuddy – Repair Shop CRM & Booking: A security weakness
RepairBuddy – Repair Shop CRM & Booking is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 17, 2026 CVE-2026-0820
RepairBuddy – Repair Shop CRM & Booking Plugin for: Broken access control
RepairBuddy – Repair Shop CRM & Booking Plugin for is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE4.3
NVDPending
Apr 04, 2025 CVE-2025-32277
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 31, 2024 CVE-2024-56061
RepairBuddy: Privilege escalation or authentication bypass
RepairBuddy is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Nov 11, 2024 CVE-2024-51793
RepairBuddy: Dangerous file upload
RepairBuddy is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE10.0
NVD9.8