CVE-2026-78138
Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.
| Vendor | unknown |
| Product | finale lite |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown finale lite
Be the first to know when new unknown vulnerabilities affecting unknown finale lite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Finale Lite
0 < 2.21.0
References
Credits
Shikhali Jamalzade WPScan