CVE-2026-4338

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:automattic:activitypub:*:*:*:*:*:wordpress:*:*

History

24 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) El plugin de WordPress ActivityPub anterior a la versión 8.0.2 no filtra adecuadamente las publicaciones a mostrar, permitiendo a usuarios no autenticados acceder a publicaciones borrador/programadas/pendientes.

14 Apr 2026, 16:23

Type Values Removed Values Added
First Time Automattic
Automattic activitypub
CPE cpe:2.3:a:automattic:activitypub:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/ - () https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/ - Third Party Advisory
CWE NVD-CWE-noinfo

08 Apr 2026, 17:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

08 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 07:16

Updated : 2026-07-24 20:10


NVD link : CVE-2026-4338

Mitre link : CVE-2026-4338

CVE.ORG link : CVE-2026-4338


JSON object : View

Products Affected

automattic

  • activitypub