CVE-2026-18364
Received Received - Intake

Privilege Escalation in zportals WordPress Plugin

Vulnerability report for CVE-2026-18364, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integration settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zportals zportals to 6.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The zportals WordPress plugin before version 6.4.2 has a vulnerability where it does not check user capabilities or use nonces for certain AJAX actions. This allows users with a subscriber-level account to modify the plugin's stored integration settings without proper authorization.

Detection Guidance

Check WordPress plugin versions using admin dashboard or run: wp plugin list --field=version --name=zportals. Verify if version is below 6.4.2. Inspect AJAX calls in browser developer tools for unauthorized settings modifications.

Impact Analysis

An attacker with a subscriber account could alter the plugin's settings, potentially leading to unauthorized changes in how the plugin integrates with other systems. This could disrupt functionality or expose sensitive data depending on the plugin's use.

Compliance Impact

This vulnerability could lead to unauthorized modifications of plugin settings, potentially violating data integrity and access control requirements in GDPR and HIPAA. Unauthorized changes may result in non-compliance with these regulations.

Mitigation Strategies

Update the zportals plugin to version 6.4.2 or later immediately. If immediate update is not possible, restrict subscriber-level accounts from accessing admin features or disable the plugin until updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart