Vulnerabilities
CVE-2026-0820 - RepairBuddy <= 4.1116 - insecure direct object reference to authenticated (subscr...
CVE ID : CVE-2026-0820 Published : Jan. 17, 2026, 3:24 a.m. | 1 hour, 1 minute ago Description : The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary signatures to any order in the system, potentially modifying order metadata and triggering unauthorized status changes. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...