PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4338 Automattic CVE debrief

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then.

Vendor
Automattic
Product
ActivityPub
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the ActivityPub WordPress plugin, particularly those with sensitive information in drafts, scheduled, or pending posts, should update to version 8.0.2 or later to prevent unauthorized access. Additionally, users with high-risk or sensitive data in their WordPress installations should review their current plugin version and consider implementing compensating controls.

Technical summary

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed. This vulnerability allows unauthenticated users to access drafts, scheduled, or pending posts. The plugin's lack of proper filtering enables unauthorized users to view sensitive information that should not be publicly accessible. Users of the plugin should take immediate action to update to version 8.0.2 or later.

Defensive priority

High priority should be given to updating the ActivityPub WordPress plugin to version 8.0.2 or later. Additionally, users should review their current plugin version and consider implementing compensating controls, such as restricting access to sensitive posts or monitoring for suspicious activity.

Recommended defensive actions

  • Update the ActivityPub WordPress plugin to version 8.0.2 or later.
  • Review current plugin version and consider implementing compensating controls.
  • Monitor for suspicious activity related to post access.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE record was published on 2026-04-08T07:16:22.400Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts. Evidence is limited to public CVE and NVD information.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then. The NVD entry is currently Analyzed.