MEDIUM
allterraindeveloper
CVE published 2026-09-25
CVE-2026-19775
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass. Authenticated attackers with custom-level access can read titles, statuses, dates, permalinks, and content excerpts of private posts, as well as content and AI-moderation verdicts of unapproved comments. This vulnerability has a medium severity level and requires defenders to [truncated]