AllCoach <= 1.0.1 - Privilege Escalation to Unauthenticated Account Takeover
highThe AllCoach plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.0.1. This is due to unauthenticated REST API endpoints (/auth/register-client and /auth/register-coach) that allowed account creation without any authentication or authorization checks. This makes it possible for...
- CVSS:
- 7.3
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.2
- Disclosed:
- Jun 15, 2026