WordPress security by component
RepairBuddy
RepairBuddy (computer-repair-shop) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Sep 10, 2026; the highest published CVSS base score is 10.
Plugin slug:
computer-repair-shopLatest vulnerability
CVE-2026-81803: RepairBuddy permits subscriber-level remote code execution
RepairBuddy through 4.1224 has a code-injection flaw that permits remote code execution by an authenticated Subscriber. The CNA rates attack complexity as high and identifies high confidentiality, integrity, and availability impact without requiring another user's interaction.
| Safe version |
|
||
|---|---|---|---|
| Sep 10, 2026 |
CVE-2026-81803
RepairBuddy permits subscriber-level remote code execution
RepairBuddy through 4.1224 has a code-injection flaw that permits remote code execution by an authenticated Subscriber. The CNA rates attack complexity as high and identifies high confidentiality, integrity, and availability impact without requiring another user's interaction.
|
4.1225 |
CVE7.5
NVDPending
|
| Aug 24, 2026 |
CVE-2026-78291
RepairBuddy exposes a state-changing operation without authentication
RepairBuddy through 4.1223 exposes an operation without the authorization it requires. An unauthenticated requester can alter protected state, producing low integrity impact.
|
4.1224 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39584
RepairBuddy: Broken access control
RepairBuddy is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.1132.
|
4.1133 |
CVE6.5
NVDPending
|
| May 26, 2026 |
CVE-2026-24638
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.1121.
|
4.1125 |
CVE4.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39586
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.1132.
|
4.1133 |
CVE5.3
NVDPending
|
| Mar 21, 2026 |
CVE-2026-3567
RepairBuddy – Repair Shop CRM & Booking: A security weakness
RepairBuddy – Repair Shop CRM & Booking is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 17, 2026 |
CVE-2026-0820
RepairBuddy – Repair Shop CRM & Booking Plugin for: Broken access control
RepairBuddy – Repair Shop CRM & Booking Plugin for is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32277
RepairBuddy: A security weakness
RepairBuddy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 31, 2024 |
CVE-2024-56061
RepairBuddy: Privilege escalation or authentication bypass
RepairBuddy is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 11, 2024 |
CVE-2024-51793
RepairBuddy: Dangerous file upload
RepairBuddy is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE10.0
NVD9.8
|