Vulnerability Description
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-19699?
CVE-2026-19699 is a vulnerability with a CVSS score of 2.7 (LOW). The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list a...
How severe is CVE-2026-19699?
CVE-2026-19699 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19699?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.