PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19775 allterraindeveloper CVE debrief

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass. Authenticated attackers with custom-level access can read titles, statuses, dates, permalinks, and content excerpts of private posts, as well as content and AI-moderation verdicts of unapproved comments. This vulnerability has a medium severity level and requires defenders to verify exposure and implement compensating controls to prevent unauthorized access to sensitive information.

Vendor
allterraindeveloper
Product
OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for WordPress environments with the OpenStation plugin installed should assess exposure and implement compensating controls to prevent unauthorized access to sensitive information.

Why it matters

CVE-2026-19775 is a medium-severity vulnerability in the OpenStation plugin for WordPress, allowing authenticated attackers to read sensitive information. Defenders should verify exposure, implement compensating controls, and prioritize remediation.

  • Verification of exposure for authenticated users with custom-level access
  • Potential unauthorized access to sensitive post and comment information
  • Need for compensating controls to monitor and limit access
  • Priority for updating or patching the OpenStation plugin

Technical summary

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows authenticated attackers with custom-level access and above to read sensitive information from private posts and unapproved comments, including titles, statuses, dates, permalinks, content excerpts, and AI-moderation verdicts. Defenders should prioritize verifying exposure and implementing compensating controls for authenticated users with custom-level access.

Defensive priority

Defenders should prioritize verifying exposure and implementing compensating controls for authenticated users with custom-level access.

Recommended defensive actions

  • Verify exposure of the OpenStation plugin in your WordPress environment
  • Restrict access to sensitive posts and comments for authenticated users
  • Implement compensating controls to monitor and limit unauthorized access
  • Review and update the plugin to the latest version if available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from the CVE Program and NVD indicates an authorization bypass vulnerability in the OpenStation plugin. Details are limited, and verification of affected versions and remediation is required.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.