PT-2026-95788 · WordPress · Bread

·

CVE-2026-4792

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bread plugin for WordPress versions prior to 2.9.13
Description Information exposure occurs due to missing authentication and authorization checks in the settings export functionality. The download settings() function, registered on the plugins loaded hook, allows execution on public pages. This enables unauthenticated attackers to retrieve all plugin configuration settings, including the protection password variable stored in plaintext, by accessing the '/?export-meeting-list=1' endpoint.
Recommendations Update the Bread plugin for WordPress to a version newer than 2.9.12. As a temporary mitigation, restrict access to the '/?export-meeting-list=1' endpoint.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4792

Affected Products

Bread