CVE-2026-9619
Received Received - Intake
Authorization Bypass in Docplanner WordPress Plugin

Publication date: 2026-06-24

Last updated on: 2026-06-24

Assigner: Wordfence

Description
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger outbound scraping of external websites and write scraped review data into the wp_dp_reviews database table, as well as send feature-request emails from the site administrator's email address.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-24
Last Modified
2026-06-24
Generated
2026-06-24
AI Q&A
2026-06-24
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
docplanner reviews_and_rating_plugin to 1.1.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The Reviews and Rating – Docplanner plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.1.4.

This vulnerability occurs because the plugin does not properly verify whether a user is authorized to perform certain actions.

As a result, authenticated users with subscriber-level access or higher can exploit this flaw to trigger outbound scraping of external websites and write the scraped review data into the plugin's database table.

Additionally, attackers can send feature-request emails from the site administrator's email address.

Impact Analysis

This vulnerability can impact you by allowing attackers with low-level authenticated access to manipulate your website's data.

Specifically, attackers can inject scraped review data into your site's database, potentially corrupting or polluting your reviews.

They can also send emails from your site administrator's email address, which could be used for phishing or to damage your site's reputation.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart