CVE-2026-1920 | arraytics Booktics Plugin up to 1.0.16 on WordPress update_item_permissions_check missing authentication
A vulnerability was found in arraytics Booktics Plugin up to 1.0.16 on WordPress. It has been rated as critical. Affected is the function Extension_Controller::update_item_permissions_check. This manipulation causes missing authentication.
The identification of this vulnerability is CVE-2026-1920. It is possible to initiate the attack remotely. There is no exploit available.