CVE-2026-78138

Summary

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.

Affected Software

VendorProductVersion RangeStatus
UnknownFinale Lite0 < 2.21.0affected

Weaknesses

  • CWE-200 Information Exposure

References