CVE-2026-3567 | sweetdaisy86 RepairBuddy Plugin up to 4.1132 on WordPress AJAX wc_rb_get_fresh_nonce nonce_name authorization
A vulnerability has been found in sweetdaisy86 RepairBuddy Plugin up to 4.1132 on WordPress and classified as critical. Affected by this issue is the function wc_rb_get_fresh_nonce of the component AJAX Handler. This manipulation of the argument nonce_name causes missing authorization.
This vulnerability appears as CVE-2026-3567. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.