← back

CVE-2026-11551

CRITICAL · 9.8
hype LIKELY HACK · 72 hack

Public PoC, urgent patching, defender triage guidance; KEV absence and same-day disclosure lower confidence slightly.

What: Branda WordPress plugin (≤3.4.29) allows unauthenticated attackers to reset arbitrary user passwords and take over accounts, including admin. CVSS 9.8 CRITICAL.

Why it matters: Public exploit confirmed in chatter; patch (3.4.31) available same-day; WordPress sites are high-value targets. Privilege escalation to admin access enables full site compromise. Not yet KEV-listed, but urgency and active patching signal real threat.

Where it's seen: Security feed automation (CVEnew, OrizonCyber, Patchstack); defensive guidance ("update to 3.4.31 now"); one post conflates with Oracle PeopleSoft (misattribution noise). No mass scanning reports yet.

RISK: CRITICAL — Unauthenticated account takeover of WordPress admin accounts; patch available but millions of sites may lag.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 6/20/2026, 6:19:31 AM

Description

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses