CVE-2026-78138

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 06:17

Updated : 2026-08-28 18:43


NVD link : CVE-2026-78138

Mitre link : CVE-2026-78138

CVE.ORG link : CVE-2026-78138


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor