rootpwn

low · CVSS v3 2.7 · EPSS 0.00139

CVE-2026-92423

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the req…

Description

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.

Scores

Severity
low
CVSS v2
3.3
CVSS v3
2.7
CVSS v4
EPSS
0.00139

← All CVEs