SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15231

LOW · CVSS 2.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Tag, Category, and Taxonomy Manager plugin for WordPress versions prior to 3.51.0 is vulnerable due to inadequate user authorization checks, enabling contributors to access and disclose information from private or draft posts they do not own. This flaw poses a significant risk to data confidentiality within WordPress sites, particularly for those managing sensitive content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.

CVE
CVE-2026-15231
Severity
LOW
CVSS
2.7
EPSS
0.22%
WordPress

Original NVD Description

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.