PT-2026-98363 · WordPress · Openstation

·

CVE-2026-19775

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin versions prior to 1.1.8
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with custom-level access or higher can access sensitive information, including the title, status, date, permalink, and a 300-character excerpt of private, draft, pending, or future posts. Additionally, they can view the content and AI-moderation verdicts of spam and unapproved comments. Users with the 'read' capability can enable the necessary AI feature by accessing the /openstation/ portal and modifying the ai.enabled variable via the POST /desktop-mode/v1/os-settings endpoint.
Recommendations Update OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin to version 1.1.8 or later. Restrict access to the POST /desktop-mode/v1/os-settings endpoint to prevent unauthorized users from enabling the AI feature.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19775

Affected Products

Openstation