Description
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read the title, status, date, permalink, and a 300-character content excerpt of any private, draft, pending, or future post, as well as the content and AI-moderation verdicts of unapproved and spam comments. Any authenticated user with the 'read' capability can self-enable the required AI feature by visiting the /openstation/ portal and toggling their own ai.enabled setting via the POST /desktop-mode/v1/os-settings endpoint, removing any practical barrier to exploitation.
Published: 2026-09-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The OpenStation WordPress plugin is vulnerable to an authorization bypass that allows any authenticated user with a “read” capability or higher to read private, draft, pending, or future post metadata and content, as well as unapproved and spam comment content and AI‑moderation results. The flaw originates from the plugin failing to verify that the requesting user is authorized to perform the action, effectively exposing sensitive information that should be restricted to higher‑privileged users.

Affected Systems

All users running the OpenStation plugin version 1.1.7 or earlier on WordPress sites are affected. The vendor is All Terra in Developer, and the product is OpenStation, which provides Desktop Windows, Dock, and Virtual Desktops for WP Admin.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, indicating moderate risk. EPSS information is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting that zero‑day exploitation is not yet known. Based on the description, it is inferred that the attack requires authentication; any user with read access can enable the AI feature via the /openstation/ portal and then exploit the flaw using the /desktop‑mode/v1/os‑settings endpoint. Because the exploit path is straightforward for authenticated users, the likelihood of exploitation in environments where the plugin is out‑of‑date remains significant for affected sites.

Generated by OpenCVE AI on September 25, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OpenStation to the latest released version that addresses the missing authorization check.
  • If an update is unavailable, remove or restrict the AI‑Copilot mode by disabling the ai.enabled setting for all users and limiting the “read” capability to administrators only.
  • Perform a site audit to confirm that no remaining users have unwanted levels of access that could exploit the vulnerability.

Generated by OpenCVE AI on September 25, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read the title, status, date, permalink, and a 300-character content excerpt of any private, draft, pending, or future post, as well as the content and AI-moderation verdicts of unapproved and spam comments. Any authenticated user with the 'read' capability can self-enable the required AI feature by visiting the /openstation/ portal and toggling their own ai.enabled setting via the POST /desktop-mode/v1/os-settings endpoint, removing any practical barrier to exploitation.
Title OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via AI Copilot Search Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-25T13:00:16.837Z

Reserved: 2026-08-13T17:38:14.879Z

Link: CVE-2026-19775

cve-icon Vulnrichment

Updated: 2026-09-25T12:56:12.767Z

cve-icon NVD

Status : Deferred

Published: 2026-09-25T07:16:53.857

Modified: 2026-09-25T14:17:18.353

Link: CVE-2026-19775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T10:15:07Z

Weaknesses