SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19699

LOW · CVSS 2.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The GutenKit WordPress plugin prior to version 2.5.0 is vulnerable due to inadequate capability checks on certain REST API endpoints, enabling users with Contributor roles and higher to access sensitive mailing-list audience metadata from the site's marketing account. This could lead to unauthorized exposure of user data, posing a privacy risk. WordPress site administrators and those utilizing the GutenKit plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-19699
Severity
LOW
CVSS
2.7
EPSS
0.22%
WordPress

Original NVD Description

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.