CVE-2026-4066Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private and draft post content from other authors via the smart-cf-relational-posts-search AJAX action. The function queries posts with post_status=any and returns full WP_Post objects including post_content, but only checks the generic edit_posts capability instead of verifying whether the requesting user has permission to read each individual post.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-24: 3Technical Details · 2026-03-24: 203-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4066 The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in… https://www.cve.org/CVERecord?id=CVE-2026-4066

    Post summary

    The text announces CVE-2026-4066, indicating an unauthorized access vulnerability in a WordPress plugin, without providing a PoC, exploit, or patch details.

    00010239
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4066 The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in… https://www.cve.org/CVERecord?id=CVE-2026-4066 ----- Traducción: CVE-2026-4066 el … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-4066, highlighting that the Smart Custom Fields WordPress plugin allows unauthorized data access due to a missing capability check, and points to the CVE record for more information.

    0000029
    60 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4066 Unauthorized Post Content Access in WordPress Smart Custom Fields Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4066

    Post summary

    The text announces CVE-2026-4066, an unauthorized post content access flaw in the WordPress Smart Custom Fields plugin, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000058
    4.0K followersView on X

Explore more