CRITICAL🇵🇱 Wersja polska

CVE-2026-11551

CVSS 9.8v3.1pub. 2026-06-20upd. 2026-06-23

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

🤖 AI Analysis
How it works

The plugin does not properly verify user identity before performing password change operations. An unauthenticated attacker can send a specially crafted request that causes the password of a selected account to be overwritten — including an account with administrator privileges. After changing the password, the attacker logs into the compromised account, gaining full access to the WordPress panel.

Impact

An attacker can completely take over any WordPress user account, including administrator accounts, giving them full control over the website — ability to modify content, install malware, and access data.

Mitigation & patch

The Branda plugin should be updated to a version higher than 3.4.29. The patch is available in the WordPress repository under changeset 3568291. Until the update is applied, it is recommended to deactivate the plugin.

Who is affected

The Branda plugin (branda-white-labeling) for WordPress in all versions up to and including 3.4.29.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassLPE
CWE
References