
CVE-2026-1867 The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it … https://www.cve.org/CVERecord?id=CVE-2026-1867
Post summary
The vulnerability in the Guest posting WordPress plugin (CVE-2026-1867) enables an attacker to inject a URL parameter to regenerate a .json file from demo data, potentially exposing sensitive information.
