CVE-2026-12906

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.
Configurations

No configuration.

History

16 Jul 2026, 18:16

Type Values Removed Values Added
CWE CWE-639
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7

16 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 07:16

Updated : 2026-07-16 18:16


NVD link : CVE-2026-12906

Mitre link : CVE-2026-12906

CVE.ORG link : CVE-2026-12906


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key