CVE · Medium

CVE-2026-32386 — Envo Extra [envo-extra] < 1.9.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32386 Envo Extra [envo-extra] < 1.9.14 Missing Authorization Medium 4.3 < 1.9.14 1.9.14 2026-02-18

CVE-2026-32386

A security flaw exists in the Envo Extra plugin for WordPress, where a critical oversight in permission checks allows users with elevated roles or higher to bypass intended restrictions on certain actions within the affected versions up through 1.9.13. This vulnerability can be exploited by authenticated attackers possessing contributor-level access or above.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.