CVE-2026-7523

The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access arbitrary private alba_card post data, including title, description, assignee, due date, tags, and comments, that is intended to be restricted to Administrators and Editors. The handler is registered via the wp_ajax_nopriv_ hook and its nonce is exposed to all site visitors through wp_localize_script on pages containing the [alba_board] shortcode, making this exploitable by unauthenticated users who can access any such page.
Configurations

No configuration.

History

05 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-05 23:16

Updated : 2026-06-17 11:02


NVD link : CVE-2026-7523

Mitre link : CVE-2026-7523

CVE.ORG link : CVE-2026-7523


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization