What the vulnerability does
01Description
Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Toolkit by WebYes: from n/a through <= 2.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
The Accessibility Toolkit by WebYes contains a missing authorization flaw that allows authenticated users with low privileges to read sensitive information they should not access. An attacker with a valid login account can view confidential data without additional interaction. This affects all versions up to 2.0.4. Update to a version newer than 2.0.4 to resolve the issue.
What an attacker can do
03Attacker Capabilities
Read sensitive information they are not authorized to access.
Potential impact on your site
04Site Impact
Authenticated users can view confidential data beyond their permission level.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege user account on the site.
Key dates
06Disclosure timeline
November 21, 2025
CVE published
April 28, 2026
Record updated