CVE-2026-11907 | xwp Stream Plugin up to 4.2.0 on WordPress Heartbeat API authorization
A vulnerability, which was classified as problematic, was found in xwp Stream Plugin up to 4.2.0 on WordPress. The affected element is an unknown function of the component Heartbeat API. Executing a manipulation can lead to authorization bypass.
This vulnerability is registered as CVE-2026-11907. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More