CVE-2026-7558
Last modified
CVE-2026-7558 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress 'init' hook, which fires for all requests, including those from unauthenticated visitors, without any capability check. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress 'init' hook, which fires for all requests, including those from unauthenticated visitors, without any capability check. This makes it possible for unauthenticated attackers to download a CSV file containing sensitive WooCommerce donation data, including order dates, order IDs, charitable donation amounts, and admin-only order edit URLs, simply by visiting any page on the site with the 'tot_export_table' GET parameter set to a numeric value (0–3).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| tokenoftrust | Age Verification & Identity Verification by Token of Trust | <= 4.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7558?
How severe is CVE-2026-7558?
How do I fix CVE-2026-7558?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7556The FV Flowplayer Video Player plugin for WordPress is vulne…7.2
- CVE-2026-75569A flaw was found in mce-operator-bundle. The build process f…7.7
- CVE-2026-7557An improper verification of cryptographic signature vulnerab…9.1
- CVE-2026-75573In MongoDB Connector for BI, mongodrdl may write a TLS priva…5.5
- CVE-2026-75574The Grav Email plugin (getgrav/grav-plugin-email) before 4.2…8.8
- CVE-2026-75575Rocket.Chat exposes the sendForgotPasswordEmail Meteor metho…5.3
- CVE-2026-75583keeper.sh's calendar module version prior to 2.18.14 contain…3.5
- CVE-2026-75584ION-DTN before 4.2.1-a.1 contains a denial of service vulner…7.5
- CVE-2026-75586The Unlimited Elements For Elementor plugin for WordPress is…6.1
- CVE-2026-75587Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact…3.3
- CVE-2026-75588Mattermost Desktop App versions <=6.2 6.2.2.0 fail to valida…2.6
- CVE-2026-75589Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HM…7.5
Are you affected by CVE-2026-7558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
