
CVE-2026-4338 The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts https://www.cve.org/CVERecord?id=CVE-2026-4338
Post summary
The post announces CVE-2026-4338, describing how the ActivityPub WordPress plugin before version 8.0.2 fails to filter posts properly, allowing unauthenticated users to view drafts and pending content.
