PT-2026-67009 · WordPress · Builderall Builder For Wordpress

CVE-2026-11882

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Builderall for WordPress versions prior to 3.0.2
Description Public OAuth authentication routes fail to bind the state value to the initiating user session. This allows unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite occurs if the site is already connected to a paid account.
Recommendations Update Builderall for WordPress to version 3.0.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11882

Affected Products

Builderall Builder For Wordpress