The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-15231
Mitre link : CVE-2026-15231
CVE.ORG link : CVE-2026-15231
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
