Description
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.
Published: 2026-07-02
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adminify WordPress plugin versions older than 4.2.10 do not enforce per‑user access checks on the results returned endpoint. This oversight permits a Contributor user to retrieve non‑public content that WordPress would normally hide, such as unpublished post titles, pending comment text, the plugin’s internal inventory of items, and other users’ account names. The flaw represents a low‑severity privacy breach governed by CWE‑200 and CWE‑285.

Affected Systems

WordPress installations that use Adminify with a version before 4.2.10 are affected, Contributor exploit via the vulnerable AJAX endpoint.

Risk and Exploitability

The CVSS score of 2.7 classifies the issue as low severity, yet it poses a confidentiality risk. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with Contributor privileges to activate the global search feature, after which the plugin returns hidden search results to the attacker.

Generated by OpenCVE AI on July 22, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Adminify plugin to version 4.2.10 or later.
  • Restrict access to the global search AJAX endpoint by adding a capability check that permits only Administrators to use it, or apply a firewall rule that blocks the endpoint for Contributor users.
  • Disable the global search feature for Contributors in the Adminify settings or through a custom code snippet that removes the feature for non‑admin roles.

Generated by OpenCVE AI on July 22, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Wed, 15 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Sat, 11 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 09 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Tue, 07 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 05 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 05 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 05 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sat, 04 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 03 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.
Title Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-02T12:34:37.068Z

Reserved: 2026-06-09T12:32:58.447Z

Link: CVE-2026-11781

cve-icon Vulnrichment

Updated: 2026-07-02T12:34:30.074Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses

No weakness.