CVE-2026-13600

8.1

AutoNetTV · AutoNetTV Relay

The AutoNetTV Relay WordPress plugin fails to perform authentication checks during scheduled tasks, allowing unauthenticated attackers to obtain administrator session cookies.

Executive summary

A high-severity authentication bypass in the AutoNetTV Relay WordPress plugin allows unauthenticated attackers to hijack administrator sessions and gain full system control.

Vulnerability

This is an improper authentication vulnerability occurring during scheduled content-synchronization tasks. The plugin fails to verify the identity of the requester, which can lead to the exposure of administrator authentication cookies to unauthenticated attackers.

Business impact

With a CVSS score of 8.1, this vulnerability presents a severe risk to organizational security. An attacker who successfully hijacks an administrator session can gain full control over the WordPress environment, leading to total data compromise, unauthorized modification of content, and potential further system exploitation.

Remediation

Immediate Action: Update the AutoNetTV Relay plugin to version 3.0.14 or later to ensure proper authentication checks are enforced.

Proactive Monitoring: Review web server and WordPress authentication logs for unusual login activity or unauthorized administrative access patterns.

Compensating Controls: Utilize a WAF to block suspicious traffic and restrict access to administrative interfaces and sensitive synchronization endpoints.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The potential for full administrative account takeover makes this a high-priority issue. It is imperative that administrators update to version 3.0.14 immediately to secure the environment against unauthorized access.