SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12906

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The RTMKit WordPress plugin prior to version 2.0.9 lacks proper capability checks in its AJAX actions, enabling users with Contributor roles to access and read the titles of private, draft, pending, scheduled, and trashed posts belonging to other users. This vulnerability poses a risk to user privacy and content confidentiality within WordPress sites. WordPress administrators and site owners should prioritize updating the plugin to mitigate potential information exposure.

CVE
CVE-2026-12906
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.