CVE-2026-81348

Summary

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.

Affected Software

VendorProductVersion RangeStatus
UnknownMy Private Site0 < 4.2.3affected

Weaknesses

  • CWE-200 Information Exposure

References