PatchSiren cyber security CVE debrief
CVE-2026-4338 Automattic CVE debrief
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then.
- Vendor
- Automattic
- Product
- ActivityPub
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the ActivityPub WordPress plugin, particularly those with sensitive information in drafts, scheduled, or pending posts, should update to version 8.0.2 or later to prevent unauthorized access. Additionally, users with high-risk or sensitive data in their WordPress installations should review their current plugin version and consider implementing compensating controls.
Technical summary
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed. This vulnerability allows unauthenticated users to access drafts, scheduled, or pending posts. The plugin's lack of proper filtering enables unauthorized users to view sensitive information that should not be publicly accessible. Users of the plugin should take immediate action to update to version 8.0.2 or later.
Defensive priority
High priority should be given to updating the ActivityPub WordPress plugin to version 8.0.2 or later. Additionally, users should review their current plugin version and consider implementing compensating controls, such as restricting access to sensitive posts or monitoring for suspicious activity.
Recommended defensive actions
- Update the ActivityPub WordPress plugin to version 8.0.2 or later.
- Review current plugin version and consider implementing compensating controls.
- Monitor for suspicious activity related to post access.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record was published on 2026-04-08T07:16:22.400Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts. Evidence is limited to public CVE and NVD information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4338 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4338
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4338 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4338
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.