{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/fleekdash-v2--2.6.2.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FleekDash V2 (\u003c= 2.6.2.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eCVE-2026-14356 is a critical authorization bypass vulnerability affecting the FleekDash V2 plugin for WordPress in all versions up to and including 2.6.2.2. The vulnerability stems from the plugin's failure to properly validate user authorization for administrative actions. This flaw allows an attacker, even one with low-level subscriber access, to modify the email address and password of any user on the platform, including site administrators.\u003c/p\u003e\n\u003cp\u003eDefenders must be aware that the plugin includes an unauthenticated endpoint at /wp-json/fleekdash/v1/register. This endpoint allows for the auto-provisioning of subscriber-level accounts even when the WordPress 'users_can_register' setting is disabled, providing the necessary authenticated context to exploit the primary credential overwrite vulnerability. This combination allows for a complete, unauthenticated-to-administrator account takeover chain, posing a significant risk to WordPress site integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a POST request to the unauthenticated /wp-json/fleekdash/v1/register endpoint to create a new subscriber-level account.\u003c/li\u003e\n\u003cli\u003eThe FleekDash plugin auto-provisions the account and returns a valid REST nonce to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker uses the new subscriber credentials to authenticate with the WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting the vulnerable plugin logic that handles user profile updates.\u003c/li\u003e\n\u003cli\u003eAttacker includes the required REST nonce to bypass intended authorization checks within the FleekDash plugin.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request and overwrites the target administrator's email address and password in the database.\u003c/li\u003e\n\u003cli\u003eAttacker uses the newly defined administrator credentials to log in, achieving full site compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to escalate privileges to the administrator level. This grants them full control over the WordPress installation, enabling the injection of malicious code, redirection of traffic, exfiltration of sensitive site data, and the potential deployment of secondary payloads or ransomware across the web server infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the FleekDash V2 plugin to a patched version beyond 2.6.2.2.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting /wp-json/fleekdash/v1/register.\u003c/li\u003e\n\u003cli\u003eUtilize the provided Sigma rule to detect attempts to access the vulnerable registration endpoint or perform unauthorized profile updates via the REST API.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user logs for unexpected administrative account credential changes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T07:19:51Z","date_published":"2026-07-30T07:19:51Z","id":"https://feed.craftedsignal.io/briefs/2026-07-fleekdash-auth-bypass/","summary":"The FleekDash V2 plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-14356) that allows authenticated attackers to overwrite user credentials, including administrative accounts, leading to full site compromise.","title":"Authorization Bypass in FleekDash V2 WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-fleekdash-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - FleekDash V2 (\u003c= 2.6.2.2)","version":"https://jsonfeed.org/version/1.1"}