← WordPress Vulnerabilities
WordPress security by component

iControlWP

iControlWP is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: worpit-admin-dashboard-plugin

CVE-2026-34901: iControlWP: Privilege escalation or authentication bypass

iControlWP is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.3.

PublishedJun 15, 2026
Known safe version5.5.4
Safe version
Jun 15, 2026 CVE-2026-34901
iControlWP: Privilege escalation or authentication bypass
iControlWP is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.3.
5.5.4
CVE9.8
NVDPending
Jan 30, 2025 CVE-2024-13742
iControlWP – Multiple WordPress Site Manager: Code execution
iControlWP – Multiple WordPress Site Manager is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending