PT-2026-63502 · WordPress · Regular Labs Extension Manager

CVE-2026-64791

·

Published

2026-07-22

·

Updated

2026-07-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Regular Labs Extension Manager (affected versions not specified)
Description Administrator routes and the processing of installation, updates, and uninstallation did not consistently enforce installation and component-management permissions. This flaw allows an unauthorized backend user or a Cross-Site Request Forgery (CSRF) attack—a technique where a malicious site tricks a user's browser into performing an unwanted action on a different site—to install, update, or remove extensions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64791

Affected Products

Regular Labs Extension Manager