CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-11882

unknowncovered by 1 sourcefirst seen 2026-08-01
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.

⚡ Watch CVE-2026-11882

Get an email if CVE-2026-11882 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-11882

CVE.org record

Embed the live status

CVE-2026-11882 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-11882 status](https://www.csirts.com/badge/CVE-2026-11882)](https://www.csirts.com/cve/CVE-2026-11882)