SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81348

LOW · CVSS 3.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The My Private Site plugin for WordPress prior to version 4.2.3 is vulnerable as it fails to enforce site-privacy access controls on specific unauthenticated front-end areas, enabling unauthorized users to access post content, comments, and URLs intended for logged-in users only. This exposure could lead to unauthorized information disclosure, compromising the privacy of site content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-81348
Severity
LOW
CVSS
3.7
EPSS
0.22%
WordPress

Original NVD Description

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.