PT-2026-98363 · WordPress · Openstation
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin versions prior to 1.1.8
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with custom-level access or higher can access sensitive information, including the title, status, date, permalink, and a 300-character excerpt of private, draft, pending, or future posts. Additionally, they can view the content and AI-moderation verdicts of spam and unapproved comments. Users with the 'read' capability can enable the necessary AI feature by accessing the
/openstation/ portal and modifying the ai.enabled variable via the POST /desktop-mode/v1/os-settings endpoint.Recommendations
Update OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin to version 1.1.8 or later.
Restrict access to the
POST /desktop-mode/v1/os-settings endpoint to prevent unauthorized users from enabling the AI feature.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstation