PatchSiren cyber security CVE debrief
CVE-2026-4338 Automattic CVE debrief
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then.
- Vendor
- Automattic
- Product
- ActivityPub
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the ActivityPub WordPress plugin, particularly those with sensitive information in drafts, scheduled, or pending posts, should update to version 8.0.2 or later to prevent unauthorized access. Additionally, users with high-risk or sensitive data in their WordPress installations should review their current plugin version and consider implementing compensating controls.
Technical summary
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed. This vulnerability allows unauthenticated users to access drafts, scheduled, or pending posts. The plugin's lack of proper filtering enables unauthorized users to view sensitive information that should not be publicly accessible. Users of the plugin should take immediate action to update to version 8.0.2 or later.
Defensive priority
High priority should be given to updating the ActivityPub WordPress plugin to version 8.0.2 or later. Additionally, users should review their current plugin version and consider implementing compensating controls, such as restricting access to sensitive posts or monitoring for suspicious activity.
Recommended defensive actions
- Update the ActivityPub WordPress plugin to version 8.0.2 or later.
- Review current plugin version and consider implementing compensating controls.
- Monitor for suspicious activity related to post access.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record was published on 2026-04-08T07:16:22.400Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts. Evidence is limited to public CVE and NVD information.
Official resources
-
CVE-2026-4338 CVE record
CVE.org
-
CVE-2026-4338 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T07:16:22.400Z and has not been modified since then. The NVD entry is currently Analyzed.