Accessiy By CodeConfig WordPress Plugin Authorization Bypass Vulnerability

Vulnerability

A vulnerability exists in the Accessiy By CodeConfig Accessibility WordPress plugin, specifically in versions through 1.0.0. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw allows authenticated users with subscriber-level access or higher to bypass authorization and alter the plugin's global accessibility settings.

Impact

Exploitation of this vulnerability allows for unauthorized modification of accessibility settings within the WordPress plugin.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Dec 6, 2025, 6:36 AM
Updated: Dec 6, 2025, 6:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.9
remediation
0.0
relevance
1.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.