Vulnerability Description
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.
CVSS Score
LOW
References
FAQ
What is CVE-2026-11781?
CVE-2026-11781 is a vulnerability with a CVSS score of 2.7 (LOW). The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege ...
How severe is CVE-2026-11781?
CVE-2026-11781 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11781?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.