MEDIUM

CVE-2026-57665

2026-06-26 CVSS v3.1
CVSS
5.3

Description

Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

Summary dbcve.org

Unauthenticated IDOR vulnerability in GravityView plugin versions 3.0.0 and below allows unauthenticated attackers to access or modify objects (such as entries, views, or other data) by directly referencing object identifiers without proper authorization validation.

Mitigation

Update GravityView to a version newer than 3.0.0. If immediate update is not possible, restrict access to affected endpoints via web server configuration or disable the plugin until patched.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.31%
Probability of exploitation in next 30 days
24.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE