MEDIUM
elemntor
CVE published 2026-10-10
CVE-2026-5727
The Hello Plus plugin for WordPress has a vulnerability that allows authenticated attackers with Contributor-level access to bypass authorization and publish their own header/footer templates and draft active templates owned by higher-privileged users. This vulnerability exists in all versions up to, and including, 1.7.7. The plugin does not properly verify that a user is authorized to perform an action, [truncated]