The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-13600
Mitre link : CVE-2026-13600
CVE.ORG link : CVE-2026-13600
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
