PT-2026-51702 · WordPress · Cornerstone

·

CVE-2026-9710

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cornerstone WordPress plugin versions prior to 7.8.8
Description The premium Cornerstone page builder, bundled with the X theme, fails to enforce capability checks on a CSS-preview request handler. Additionally, the nonce required to call this handler is exposed to all logged-in users on any wp-admin page. This allows any authenticated user to evaluate dynamic content tokens against arbitrary users, leading to the disclosure of sensitive metadata, including raw password hashes.
Recommendations Update the Cornerstone WordPress plugin to version 7.8.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9710

Affected Products

Cornerstone