MEDIUM
techeshta
CVE published 2026-08-05
CVE-2026-7726
The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This allows unauthenticated attackers to force the WordPress server to issue outbound HTTP requests to the plugin vendor's external API and write J [truncated]