AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18943

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WPC Admin Columns plugin for WordPress prior to version 2.3.4 lacks proper authorization checks in its AJAX actions, enabling users with minimal permissions, such as subscribers, to access sensitive metadata related to users, posts, and terms, including that of administrators. This vulnerability poses a significant risk of data exposure and privacy breaches. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential unauthorized access to sensitive information.

CVE
CVE-2026-18943
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.