CVE-2026-78149
N/A
N/A
Summary
The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Smart Post | 4.0.0 < 4.0.8 | affected |
Weaknesses
- CWE-200 Information Exposure
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.