PT-2026-31089 · WordPress · Activitypub

·

CVE-2026-4338

·

Published

2026-04-08

·

Updated

2026-04-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ActivityPub WordPress plugin versions prior to 8.0.2
Description The ActivityPub WordPress plugin does not properly filter posts, allowing unauthenticated users to access drafts, scheduled, and pending posts.
Recommendations Update to version 8.0.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-4338

Affected Products

Activitypub