WordPress · Activitypub · CVE-2026-4338
Name of the Vulnerable Software and Affected Versions
ActivityPub WordPress plugin versions prior to 8.0.2
Description
The ActivityPub WordPress plugin does not properly filter posts, allowing unauthenticated users to access drafts, scheduled, and pending posts.
Recommendations
Update to version 8.0.2 or later.