CRITICAL 9.8 CVE-2026-85681 Published 12 Sept 2026

WordPress WP Component Plugin Option Overwrite Vulnerability

Worried this affects one of your servers?

The WP Component WordPress plugin, up to version 2.2.4, lacks capability and nonce checks on an action accessible to unauthenticated users.

This allows attackers to overwrite any site option by providing both the option name and value in the request.

Impact: On a single site installation, this can lead to a full site takeover by enabling registration with a default administrator role.

Reference: CVE-2026-85681 on NVD

← Back to Security News