Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.3
Canto Plugin for WordPress: Unauthorized Access to Settings
CVE-2026-6441
Summary
The Canto plugin for WordPress has a security issue in versions up to 3.1.1 that allows anyone with a subscriber account or higher to change or delete important settings, including those related to scheduling and cron jobs. This could potentially be exploited by attackers to disrupt the plugin's functionality. To fix this, update the plugin to version 3.1.2 or higher.
Original title
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOp...
Original description
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function, which is exposed via two AJAX hooks: wp_ajax_updateOptions (class-canto.php line 231) and wp_ajax_fbc_updateOptions (class-canto-settings.php line 76). Both hooks are registered exclusively under the wp_ajax_ prefix (requiring only a logged-in user), with no call to current_user_can() or check_ajax_referer(). This makes it possible for authenticated attackers with subscriber-level access and above to arbitrarily modify or delete plugin options controlling cron scheduling behavior (fbc_duplicates, fbc_cron, fbc_schedule, fbc_cron_time_day, fbc_cron_time_hour, fbc_cron_start) and to manipulate or clear the plugin's scheduled WordPress cron event (fbc_scheduled_update).
nvd CVSS3.1
4.3
Vulnerability type
CWE-862
Missing Authorization
- https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/class-canto...
- https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/class-canto...
- https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/class-canto...
- https://plugins.trac.wordpress.org/browser/canto/trunk/includes/class-canto-sett...
- https://plugins.trac.wordpress.org/browser/canto/trunk/includes/class-canto.php#...
- https://plugins.trac.wordpress.org/browser/canto/trunk/includes/class-canto.php#...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c1a0200f-9861-4eca-adb...
Published: 17 Apr 2026 · Updated: 17 Apr 2026 · First seen: 17 Apr 2026