{"id":"CVE-2026-5727","title":"The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7","summary":"The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possibl…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-862"],"published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T05:16:40.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5727","references":[{"url":"https://plugins.trac.wordpress.org/changeset/3537433/hello-plus/trunk/modules/template-parts/components/document.php","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3537433/hello-plus/trunk/modules/template-parts/documents/ehp-document-base.php","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f1e0b89-9bac-4a3b-bb8c-278449789214?source=cve","label":"security@wordfence.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T05:23:33.493Z","slug":"CVE-2026-5727","body":"## Overview\n\nThe Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}