CVE-2026-4338
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
6th
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
| Vendor | unknown |
| Product | activitypub |
| Published | Apr 8, 2026 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown activitypub
Be the first to know when new high vulnerabilities affecting unknown activitypub are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / ActivityPub
0 < 8.0.2
References
Credits
ryuk (kos0ng) WPScan