PatchSiren cyber security CVE debrief
CVE-2026-40801 Wordable CVE debrief
A Subscriber Broken Access Control vulnerability exists in Wordable plugin versions up to 8.2.10. This issue allows unauthorized access to subscriber data. Wordable plugin users should assess exposure and prioritize verification.
- Vendor
- Wordable
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Wordable plugin users, particularly those with subscriber data, should assess exposure and prioritize verification.
Why it matters
A Subscriber Broken Access Control vulnerability exists in Wordable plugin versions up to 8.2.10, allowing unauthorized access to subscriber data. Wordable plugin users should assess exposure and prioritize verification.
- Verify exposure of Wordable plugin versions up to 8.2.10
- Potential unauthorized access to subscriber data
Technical summary
The Wordable plugin up to version 8.2.10 is vulnerable to Subscriber Broken Access Control. This issue allows unauthorized access to subscriber data.
Defensive priority
Defenders should verify exposure and apply patches if available.
Recommended defensive actions
- Verify exposure of Wordable plugin versions up to 8.2.10
- Apply patches if available
- Monitor for unauthorized access attempts
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the scope of affected versions and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40801 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40801
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40801 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40801
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.