
CVE-2026-1987 The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_w… https://www.cve.org/CVERecord?id=CVE-2026-1987
Post summary
The post announces that the Scheduler Widget plugin for WordPress has an IDOR vulnerability in all versions up to 0.1.6, without mentioning any PoC, exploit, active usage, or remediation.

