CVE-2026-2001Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-16: 5Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 502-16
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2001 The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' functio… https://www.cve.org/CVERecord?id=CVE-2026-2001

    Post summary

    The WowRevenue WordPress plugin has a missing capability check in 'Notice::install_activate_plugin', enabling unauthorized plugin installation; no exploit, patch, or active exploitation is reported.

    00010661
    56.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2001 WordPress WowRevenue Plugin Vulnerability Allows Unauthorized Plugin Installation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2001

    Post summary

    This is a disclosure of CVE‑2026‑2001 affecting the WordPress WowRevenue plugin, which permits unauthorized plugin installation.

    0001069
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2001 - High The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to,... https://www.thehackerwire.com/vulnerability/CVE-2026-2001/ https://t.co/PsOxWluUG1

    Post summary

    The WowRevenue WordPress plugin is vulnerable to unauthorized plugin installation because of a missing capability check, with the CVE disclosed but no PoC, exploit, or patch details provided.

    0000035
    112 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2001: HIGH] WordPress WowRevenue plugin up to 2.1.3 allows arbitrary plugin installation by authenticated attackers. Missing checks make remote code execution possible. #cybersecurity#cve,CVE-2026-2001,#cybersecurity https://cvefind.com/CVE-2026-2001

    Post summary

    The post announces CVE‑2026‑2001, a WordPress WowRevenue plugin flaw that allows authenticated attackers to install arbitrary plugins and potentially execute remote code due to missing validation checks.

    0000065
    580 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    General

    🚨 HIGH severity alert: CVE-2026-2001 lets subscriber users install plugins in WowRevenue WordPress plugin (all versions ≤2.1.3). RCE risk for e-commerce sites — restrict permissions & monitor installs! 🔒 https://radar.offseq.com/threat/cve-2026-2001-cwe-862-missing-authorizati... https://t.co/ld2RCWeMZ6

    Post summary

    High severity alert on CVE‑2026‑2001, which lets subscriber users install plugins in WowRevenue WordPress (≤2.1.3) leading to RCE; recommends restricting permissions and monitoring installs.

    0000036
    265 followersView on X

Explore more