Privilege Escalation Vulnerability in Branda Plugin for WordPress
⚠️ CVE-Referenzen:
CVE-2026-11551
WordPress - Branda – White Label & Branding, Free Login Page Customizer - CRITICAL - CVE-2026-11551.
The Branda plugin for WordPress contains a security flaw that allows attackers to exploit privilege escalation through account takeover. In all versions up to 3.4.29, this vulnerability stems from insufficient validation of user identities during the password update process. As a result, unauthorized individuals can change the passwords of arbitrary users, including administrators, effectively gaining access to their accounts without authentication. Website owners are strongly advised to review and update their plugin to the latest version to safeguard against potential breaches.
Quelle: securityvulnerability.io