CVE-2026-11882 PUBLISHED

Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes

Assigner: WPScan
Reserved: 10.06.2026 Published: 01.08.2026 Updated: 01.08.2026

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.

Product Status

Vendor Unknown
Product Builderall for WordPress
Versions Default: unaffected
  • affected from 0 to 3.0.2 (excl.)

Credits

  • Pablo González and Fran Ramírez finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE