CVE-2026-15231

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-15231

Mitre link : CVE-2026-15231

CVE.ORG link : CVE-2026-15231


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key