Loading market data...
← Back to CVE feed

CVE-2026-78149

UNKNOWN View on NVD ↗

Description

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.

Published: Sep 05, 2026 07:17 UTC Modified: Sep 05, 2026 07:17 UTC