---
id: CVE-2026-85681
title: >-
  The WP Component WordPress plugin through 2.2.4 does not have any capability
  or nonce checks on one of the actions it makes available to unauthenticated
  users, and it takes both the option name and the option value from the
  request, allo…
summary: >-
  The WP Component WordPress plugin through 2.2.4 does not have any capability
  or nonce checks on one of the actions it makes available to unauthenticated
  users, and it takes both the option name and the option value from the
  request, allo…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: WP Component
affected:
  - wp_component <= 2.2.4
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85681'
references:
  - url: 'https://wpscan.com/vulnerability/c602bd9e-a825-4990-a66b-1403bbeb2cee/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00498
epssPercentile: 0.40056
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-12T15:18:38.634427Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
