CVE-2026-87848
Beschrijving NL
De MPCX Lightbox WordPress-plug-in 1.2.2 tot en met 1.2.5 heeft geen toestemming of authenticatie voor een van zijn AJAX-ACTIES die beschikbaar zijn voor niet-geverifieerde gebruikers, en controleert ook niet de status van het gevraagde bericht, waardoor niet-geverifieerde bezoekers de titel, inhoud of uittreksel van willekeurige berichten kunnen ophalen, waaronder privé-, concept-, hangende, verwijderde en met een wachtwoord beveiligde berichten.
Origineel (Engels) tonen
The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones.