CVE-2026-81294 is an unauthenticated privilege-escalation vulnerability in the WordPress Authorizer plugin through version 3.15.1. The weakness is classified as CWE-266, Incorrect Privilege Assignment. Specific vulnerable code paths and exploit mechanics are not available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file repository is a local reproduction pack and Python proof of concept for CVE-2026-81294, an unauthenticated privilege-escalation issue in the WordPress Authorizer plugin through version 3.15.1. The main Python program is a standard-library HTTP client: it starts the external=oauth2 login route, stores Set-Cookie values, follows redirects, and requests a lab-only witness URL to determine whether an OAuth identity with an unverified email was mapped to an existing privileged WordPress account. It is not a scanner and is constrained by its hardcoded loopback target. No reverse shell, arbitrary command execution, file write, user-creation, or destructive behavior is present. The lab directory provides Docker Compose configuration for WordPress 6.4/PHP 8.2 Apache and MySQL 8.0, publishing WordPress exclusively as 127.0.0.1:8088 and mounting a local Authorizer plugin tree. README.md documents the expected vulnerable flow, affected and patched versions, lab preconditions, and remediation; LICENSE is AGPLv3.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated privilege-escalation vulnerability affecting Authorizer versions 3.15.1 and earlier.
An unauthenticated privilege-escalation vulnerability affecting Authorizer versions through 3.15.1. The listed CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a critical, remotely exploitable flaw requiring no privileges or user interaction, with high impact to confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.