MEDIUM
rocklobsterinc
CVE published 2026-09-07
CVE-2026-12853
The Flamingo plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with contributor-level access to enumerate taxonomy terms, potentially revealing internal form purposes, department names, or workflow identifiers. This requires immediate assessment and remediation priority for WordPress installations using the plugin, especially those with contributor-level access o [truncated]