WordPress security by component
iControlWP
Plugin description
iControlWP is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
worpit-admin-dashboard-pluginLatest vulnerability
CVE-2026-34901: iControlWP: Privilege escalation or authentication bypass
iControlWP is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.3.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-34901
iControlWP: Privilege escalation or authentication bypass
iControlWP is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.3.
|
5.5.4 |
CVE9.8
NVDPending
|
| Jan 30, 2025 |
CVE-2024-13742
iControlWP – Multiple WordPress Site Manager: Code execution
iControlWP – Multiple WordPress Site Manager is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|