High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 14, 2026
CVE-2026-4338
CVE-2026-4338
Description
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.