CVE-2026-18943
WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.
| Vendor | unknown |
| Product | wpc admin columns |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpc admin columns
Be the first to know when new unknown vulnerabilities affecting unknown wpc admin columns are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPC Admin Columns
0 < 2.3.4
References
Credits
Farid Narimanov WPScan