The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 07:17
Updated : 2026-09-08 19:09
NVD link : CVE-2026-78149
Mitre link : CVE-2026-78149
CVE.ORG link : CVE-2026-78149
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
