CVE-2026-4604

MEDIUM

Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update

Title source: cna
STIX 2.1

Description

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the plugin's settings, including the Klubraum API token and introduction text, effectively hijacking the plugin's integration with the Klubraum service.

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
klubraum/Klubraum Membership Request < 1.1.0
Published Jul 29, 2026
Tracked Since Jul 29, 2026