CVE Explorer
CVE-2026-11781
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Adminify","vendor":"Unknown","versions":[{"lessThan":"4.2.10","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9b8f7b6b26a4022dc29ec54c055cff1b281f619b6afa9e2ab1ab9c0a43e569f7 · sha256:bc938002f3649228… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9b8f7b6b26a4022dc29ec54c055cff1b281f619b6afa9e2ab1ab9c0a43e569f7 · sha256:bc938002f3649228… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9b8f7b6b26a4022dc29ec54c055cff1b281f619b6afa9e2ab1ab9c0a43e569f7 · sha256:bc938002f3649228… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/0aa18fe0-2d64-45dc-9eab-9587d63853be/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9b8f7b6b26a4022dc29ec54c055cff1b281f619b6afa9e2ab1ab9c0a43e569f7 · sha256:bc938002f3649228… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.