WordPress · Cornerstone · CVE-2026-9710
**Name of the Vulnerable Software and Affected Versions**
Cornerstone WordPress plugin versions prior to 7.8.8
**Description**
The premium Cornerstone page builder, bundled with the X theme, fails to enforce capability checks on a CSS-preview request handler. Additionally, the nonce required to call this handler is exposed to all logged-in users on any wp-admin page. This allows any authenticated user to evaluate dynamic content tokens against arbitrary users, leading to the disclosure of sensitive metadata, including raw password hashes.
**Recommendations**
Update the Cornerstone WordPress plugin to version 7.8.8 or later.