Impact
The Adminify WordPress plugin before version 4.2.10 fails to enforce per‑user read‑capability checks on the results of its global search AJAX feature. This omission enables a user with the low‑privilege Contributor role to retrieve information normally hidden from lower‑privilege roles, such as unpublished post titles, pending comment content, the plugin’s internal inventory data, and other users’ account names.
Affected Systems
WordPress sites that install the Adminify plugin older than 4.2.10 are affected. Any authenticated user with a Contributor role can trigger the vulnerable global search AJAX endpoint via the Adminify interface and receive sensitive search results. The issue does not affect unauthenticated users or those with higher‑privilege roles, as the plugin generally exposes such data to administrators.
Risk and Exploitability
The disclosed functionality is reflected in the CVSS score of 2.7, indicating low severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker must be authenticated as a Contributor and must initiate the global search AJAX request within the Adminify interface to extract the exposed data. The impact is a confidentiality breach, exposing non‑public content that WordPress otherwise protects.
OpenCVE Enrichment