PT-2026-54616 · WordPress · Adminify
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adminify WordPress plugin versions prior to 4.2.10
Description
An issue exists in an administration search feature that fails to perform per-user read-capability checks on returned results. This allows users with low-privilege roles, such as Contributor, to disclose non-public content that is normally restricted, including unpublished post titles from other authors, pending comment content, user account names, and the plugin inventory.
Recommendations
Update Adminify WordPress plugin to version 4.2.10 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adminify