WordPress security by component
WP Component
WP Component (wp-component) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
wp-componentLatest vulnerability
CVE-2026-85681: WP Component lets unauthenticated callers overwrite site options
WP Component through 2.2.4 exposes an unauthenticated action with no capability or nonce check and accepts both the WordPress option name and value from the request. An attacker can overwrite arbitrary options; on a single-site installation, enabling registration and setting the default role to administrator leads to full takeover. The authoritative export does not name the action or parameters.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-85681
WP Component lets unauthenticated callers overwrite site options
WP Component through 2.2.4 exposes an unauthenticated action with no capability or nonce check and accepts both the WordPress option name and value from the request. An attacker can overwrite arbitrary options; on a single-site installation, enabling registration and setting the default role to administrator leads to full takeover. The authoritative export does not name the action or parameters.
|
See mitigation notes |
CVE9.8
NVDPending
|