Sploitus

CVE-2026-11551

4 known exploits for CVE-2026-11551

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

Affected products
Branda
CVSS 3.1
9.8 CRITICAL
EPSS
0.6% (47th percentile)
Weakness
CWE-640
NVD status
Deferred
Published
2026-06-19
CVE-2026-11551 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2026-11551

Proof-of-concept code and exploit modules indexed by Sploitus