๐Ÿ” CVE Alert

CVE-2026-4338

HIGH 7.5

ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
6th

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

Vendor unknown
Product activitypub
Published Apr 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown activitypub

Be the first to know when new high vulnerabilities affecting unknown activitypub are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ActivityPub
0 < 8.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/

Credits

ryuk (kos0ng) WPScan