CVE-2026-48888 is an Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce, which allows for an HTTP DoS. The issue affects WooCommerce from n/a before 11.1.0. This vulnerability requires verification and possible remediation. Defenders responsible for e-commerce systems using WooCommerce, especially those with publicly accessible online stores, should assess potenti [truncated]
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowing unauthenticated users to access drafts, scheduled, or pending posts. This vulnerability has a high impact on users with sensitive information in drafts, scheduled, or pending posts. Users should update to version 8.0.2 or later to prevent unauthorized access. The CVE record was published on 2026-04-08T07 [truncated]