HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-42677Published Modified CNA Patchstack

CVE-2026-42677: WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
4.0.0
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a broken access control vulnerability in the WP Document Revisions WordPress plugin, versions up to and including 3.8.1. The flaw is reachable over the network without any authentication, meaning an unauthenticated remote attacker can send crafted requests to exploit misconfigured authorization checks. Successful exploitation allows an attacker to read documents and revisions that should be restricted, disclosing confidential content. A patched-image rebuild at version 4.0.0 is available on HarborGuard for environments running an affected version of this plugin.

HarborGuard Coverage

Detection

Detection of CVE-2026-42677 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds including Patchstack and NVD. This capability covers both upstream base images and custom-built images that bundle the WP Document Revisions plugin directly.

Available
Triage

HarborGuard is capable of scoring this CVE at 7.5 HIGH using the CVSS v3.1 vector and weighting it against each customer organization's per-environment compliance policy. Triage routing is available to direct findings to the appropriate team inbox based on policy configuration within each customer org.

Available
Patch

A patched-image rebuild targeting WP Document Revisions 4.0.0 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable endpoint is exposed over the network, so the attacker must be able to reach the WordPress service via HTTP/HTTPS from a remote location.

  • AuthenticationNot required

    No account or session credentials are needed; the authorization check is entirely absent for the affected requests.

  • Victim interactionNot required

    The attack is fully server-side and does not require any action from a logged-in user or site visitor.

  • Attack complexityDetail

    Exploitation is reliable and condition-free, requiring no race conditions, special memory layout, or environmental setup beyond network access to the target.

Blast Radius

  • An attacker reads documents and document revisions stored in WordPress that are intended to be access-controlled, including any confidential files uploaded through the plugin.
  • No write or delete capability is conferred by this vulnerability; data integrity and availability are unaffected.
  • Exposed documents may include internal drafts, legal files, or other sensitive content depending on how the site uses the plugin.
  • If documents contain credentials or personal data, downstream account compromise or compliance violations are a direct consequence of disclosure.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any image found bundling WP Document Revisions below version 4.0.0, including custom WordPress images built internally. The finding is scored at 7.5 HIGH and routed according to each environment's compliance policy configuration. Where compliance policy permits auto-remediation, HarborGuard can rebuild the image at the fixed version 4.0.0, execute a regression run, and open a pull request against affected workloads. For high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes for environments with auto-remediation enabled. Customers who review and merge PRs manually will find the rebuilt image and test results attached to the PR for straightforward review.

See how HarborGuard automates this

Fix available

4.0.0
Affected packages
  • Ben Balter / WP Document Revisions
    < 4.0.0 (from n/a)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References