LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-11551

Published
CVSS9.8
Severitycritical
WeaknessCWE-640
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-11551

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-11551.