WordPress · Adminify · CVE-2026-11781
**Name of the Vulnerable Software and Affected Versions**
Adminify WordPress plugin versions prior to 4.2.10
**Description**
An issue exists in an administration search feature that fails to perform per-user read-capability checks on returned results. This allows users with low-privilege roles, such as Contributor, to disclose non-public content that is normally restricted, including unpublished post titles from other authors, pending comment content, user account names, and the plugin inventory.
**Recommendations**
Update Adminify WordPress plugin to version 4.2.10 or later.