Authorizer

Authorizer has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 8.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high.

The most common weakness is Improper Privilege Management, behind 1 of the records (50%). Other recurring categories include Improper Validation Of Specified Type Of Input.

Every one of the 2 issues recorded for Authorizer has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Authorizer is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
8.9/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Authorizer vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-81294

Authorizer <= 3.15.1 - Unauthenticated Privilege Escalation

Read the full analysis

Vulnerability Records

2 records
Authorizer banner
Latestv3.15.3

Authorizer

Paul Ryan

Author

Paul Ryan

5.0(20)
100/100
Last Updated
2026-09-02 (10d ago)
Active Installs
5,000+
Downloads
207,556
Requires WP
5.9+
Requires PHP
8.1+
Tested up to
WP 7.1
Created
2015-04-01 (12y ago)

Authorizer restricts access to a WordPress site to specific users, typically students enrolled in a university course. It maintains a list of approved users that you can edit to determine who has access. It also replaces the default WordPress login/authorization system with one relying on an external server, such as Google, CAS, LDAP, or an OAuth2 provider. Finally, Authorizer lets you limit invalid login attempts to prevent bots from compromising your users’ accounts. View or contribute to the plugin source on GitHub: https://github.com/uhm-coe/authorizer Authorizer requires the following: CAS server (2.x, 3.x, 4.x, 5.x, 6.x, or 7.x) or LDAP server (plugin needs the URL) PHP extensions: php-ldap, php-curl, php-dom Authorizer provides the following options: Authentication: WordPress accounts; Google accounts; CAS accounts; LDAP accounts; OAuth2 accounts Login Access: All authenticated users (all local and all external can log in); Only specific users (all local and approved external users can log in) View Access: Everyone (open access); Only logged in users Limit Login Attempts: Progressively increase the amount of time required between invalid login attempts. Shortcode: Use the [authorizer_login_form] shortcode to embed a wp_login_form() outside of wp-login.php.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C