PT-2026-60705 · WordPress · Fense Proxy & Vpn Blocker

·

CVE-2026-8616

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fense Proxy & VPN Blocker versions prior to 3.0.2
Description Unauthorized modification of data is possible due to a missing capability check and missing nonce validation in the fense bpvt save settings() function. The callback is registered to both wp ajax * and wp ajax nopriv * hooks and unconditionally calls delete option() on four plugin options and delete transient() on three transients related to the plugin's API key cache and settings. This allows unauthenticated attackers to delete plugin options and transients, resetting the API key and data cache, which forces the plugin to refetch state.
Recommendations Update to a version newer than 3.0.1. As a temporary mitigation, restrict access to the fense bpvt save settings() function.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8616

Affected Products

Fense Proxy & Vpn Blocker