๐Ÿ” CVE Alert

CVE-2026-18943

UNKNOWN 0.0

WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.

Vendor unknown
Product wpc admin columns
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpc admin columns

Be the first to know when new unknown vulnerabilities affecting unknown wpc admin columns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPC Admin Columns
0 < 2.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9f2f3db0-1031-4e16-96f2-12a02b97ad06/

Credits

Farid Narimanov WPScan