CVE-2026-13600
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
| Vendor | unknown |
| Product | autonettv relay |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown autonettv relay
Be the first to know when new unknown vulnerabilities affecting unknown autonettv relay are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / AutoNetTV Relay
0 < 3.0.14
References
Credits
moonge WPScan