CVE Database /
CVE-2026-32386
CVE · Medium
CVE-2026-32386 — Envo Extra [envo-extra] < 1.9.14
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-32386
|
Envo Extra [envo-extra] < 1.9.14 |
Missing Authorization |
Medium
4.3
|
< 1.9.14
|
1.9.14 |
2026-02-18 |
—
|
CVE-2026-32386
A security flaw exists in the Envo Extra plugin for WordPress, where a critical oversight in permission checks allows users with elevated roles or higher to bypass intended restrictions on certain actions within the affected versions up through 1.9.13. This vulnerability can be exploited by authenticated attackers possessing contributor-level access or above.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings