PT-2026-31089 · WordPress · Activitypub

Ryuk

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-4338

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ActivityPub WordPress plugin versions prior to 8.0.2
Description The ActivityPub WordPress plugin does not properly filter posts, allowing unauthenticated users to access drafts, scheduled, and pending posts.
Recommendations Update to version 8.0.2 or later.

Exploit

Fix

Related Identifiers

CVE-2026-4338

Affected Products

Activitypub