CVE-2026-15231

Summary

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.

Affected Software

VendorProductVersion RangeStatus
UnknownTag, Category, and Taxonomy Manager0 < 3.51.0affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References