CVE-2026-1060Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/adminify/v1/get-addons-list REST API endpoint. The endpoint is registered with permission_callback set to __return_true, allowing unauthenticated attackers to retrieve the complete list of available addons, their installation status, version numbers, and download URLs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-28: 3Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 301-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1060 Unauthenticated Sensitive Information Exposure in WP Adminify WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1060

    Post summary

    The text announces CVE-2026-1060, an unauthenticated info‑exposure flaw in WP Adminify, but provides no further details on exploits, patches, or PoC.

    0000061
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-1060: WP Adminify exposes addon list via a public REST endpoint, leaking versions & download URLs to anyone. Update to 4.0.7.8 now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-1060 #WordPress #infosec #AppSec

    Post summary

    The advisory reports that CVE-2026-1060 causes an addon list disclosure via WP Adminify's REST endpoint and recommends updating to version 4.0.7.8 to patch the vulnerability.

    0000054
    51 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1060 The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/adminify/v1/get-addo… https://www.cve.org/CVERecord?id=CVE-2026-1060

    Post summary

    The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 4.0.7.7, accessed via the /wp-json/adminify/v1/get-addo endpoint.

    00000192
    56.5K followersView on X

Explore more