The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-i [truncated]
CVE-2026-54844 is a HIGH-severity vulnerability with a CVSS score of 7.5, affecting CheckView Automated Testing versions up to 2.1.0. The vulnerability is caused by unauthenticated broken access control. The CVE was published on 2026-06-25T14:16:48.560Z and last modified on 2026-06-29T18:16:38.010Z. The vendor, Unknown Vendor, has a low confidence level and needs review. Patchstack reported this vulnerability.