VYPR
Low severity2.7NVD Advisory· Published Aug 20, 2026· Updated Aug 26, 2026

CVE-2026-19699

CVE-2026-19699

Description

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1