An unauthenticated attacker can exploit CVE-2026-11551, a critical privilege escalation vulnerability in the WordPress Branda plugin up to version 3.4.29, by leveraging improper identity validation to change arbitrary user passwords, including administrators, leading to full account takeover and potential compromise of the WordPress site.
PoC
Branda plugin
wordpress
plugin
vulnerability
privilege-escalation
account-takeover
web-application
2r
2t
1c
updated