MEDIUM
CVE-2026-57665
CVSS
5.3
Description
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
Summary dbcve.org
Unauthenticated IDOR vulnerability in GravityView plugin versions 3.0.0 and below allows unauthenticated attackers to access or modify objects (such as entries, views, or other data) by directly referencing object identifiers without proper authorization validation.
Mitigation
Update GravityView to a version newer than 3.0.0. If immediate update is not possible, restrict access to affected endpoints via web server configuration or disable the plugin until patched.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.