CVE-2026-66677

WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.


We have discovered 513 live websites that are affected by CVE-2026-66677.

Run a Free Instant Scan




Affected Software

Product  Leyka
Category Wordpress Plugins
Vulnerable Domains513 live websites (100% of Leyka install base)
Vulnerable Versions
  • from 0 through 3.32.3
Vulnerable Versions Count49 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • Jakub Herman | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66677
United States2 websites



Russia502 websites
Germany3 websites
Ukraine3 websites
Denmark1 websites
Kazakhstan1 websites
Singapore1 websites

Website Distribution by TLD

Number of websites using CVE-2026-66677
.ru391 websites
.com24 websites
.org23 websites
.net9 websites
.info4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66677

Top websites that are affected by CVE-2026-66677. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.ru Russia***,***
***.***.ru Russia***,***
**********.ru Russia***,***
**************.ru Russia***,***
*********.ru Russia***,***
***********.ru Russia***,***
******.com Russia***,***
************.ru Russia***,***
**************.ru Russia*,***,***
****.ru Russia*,***,***
See full domain list

FAQ

CVE-2026-66677 is Authentication Bypass Using an Alternate Path or Channel in Leyka
A total of 513 websites have been identified as vulnerable to CVE-2026-66677, based on global website indexing conducted by WebTechSurvey.
The Leyka is affected by the CVE-2026-66677 vulnerability.
Leyka versions up to and including 3.32.3 are vulnerable to CVE-2026-66677.