PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4338 Automattic CVE debrief

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then.

Vendor
Automattic
Product
ActivityPub
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the ActivityPub WordPress plugin, particularly those with sensitive information in drafts, scheduled, or pending posts, should update to version 8.0.2 or later to prevent unauthorized access. Additionally, users with high-risk or sensitive data in their WordPress installations should review their current plugin version and consider implementing compensating controls.

Technical summary

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed. This vulnerability allows unauthenticated users to access drafts, scheduled, or pending posts. The plugin's lack of proper filtering enables unauthorized users to view sensitive information that should not be publicly accessible. Users of the plugin should take immediate action to update to version 8.0.2 or later.

Defensive priority

High priority should be given to updating the ActivityPub WordPress plugin to version 8.0.2 or later. Additionally, users should review their current plugin version and consider implementing compensating controls, such as restricting access to sensitive posts or monitoring for suspicious activity.

Recommended defensive actions

  • Update the ActivityPub WordPress plugin to version 8.0.2 or later.
  • Review current plugin version and consider implementing compensating controls.
  • Monitor for suspicious activity related to post access.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE record was published on 2026-04-08T07:16:22.400Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts. Evidence is limited to public CVE and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-4338 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-4338

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-4338 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4338

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.