What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through < 4.11.2.
Explanation of Vulnerability in Simple Terms
02Summary
WpStream versions up to 4.11.2 contain an authorization flaw that allows authenticated users to modify data or disrupt service availability. An attacker with low-level account access can exploit this without user interaction. The vulnerability does not expose sensitive information but can compromise data integrity and site stability. Update to version 4.12.3 or later.
What an attacker can do
03Attacker Capabilities
Modify site data or cause temporary unavailability without elevated privileges.
Potential impact on your site
04Site Impact
Authenticated users can alter content or disrupt service; data integrity and uptime at risk.
Conditions required to exploit
05Prerequisites
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
06Disclosure timeline
April 8, 2026
CVE published
April 29, 2026
Record updated