← WordPress Vulnerabilities
WordPress security by component

WP Component

WP Component (wp-component) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: wp-component

CVE-2026-85681: WP Component lets unauthenticated callers overwrite site options

WP Component through 2.2.4 exposes an unauthenticated action with no capability or nonce check and accepts both the WordPress option name and value from the request. An attacker can overwrite arbitrary options; on a single-site installation, enabling registration and setting the default role to administrator leads to full takeover. The authoritative export does not name the action or parameters.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-component
Safe version
Sep 12, 2026 CVE-2026-85681
WP Component lets unauthenticated callers overwrite site options
WP Component through 2.2.4 exposes an unauthenticated action with no capability or nonce check and accepts both the WordPress option name and value from the request. An attacker can overwrite arbitrary options; on a single-site installation, enabling registration and setting the default role to administrator leads to full takeover. The authoritative export does not name the action or parameters.
See mitigation notes
CVE9.8
NVDPending