Description
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access to WordPress Posts via the plugin
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass WordPress permissions when interacting with the plugin’s post listing functionality. This flaw permits the attacker to view, edit, or delete content that is normally restricted to privileged users, potentially leading to data exposure or content tampering.

Affected Systems

WordPress sites that have the Advanced Posts Listing – Show Post List Easily plugin version 1.0.8 or earlier installed and activated. The plugin is developed by Flipper Code and is used in any WordPress installation that includes it.

Risk and Exploitability

The CVSS score of 7.5 indicates high risk. Although there is no EPSS data, the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Attackers can exploit the flaw by sending crafted requests to the plugin’s endpoints without authentication, immediately accessing restricted resources. The lack of additional prerequisites makes exploitation likely for affected sites.

Generated by OpenCVE AI on October 6, 2026 at 11:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Advanced Posts Listing – Show Post List Easily plugin to version 1.0.9 or later released by Flipper Code.
  • If an update is not immediately feasible, temporarily disable or delete the plugin from the WordPress installation to eliminate the abuse vector.
  • As a short‑term hardening measure, restrict direct access to the plugin’s administrative URLs by configuring WordPress or the web server to allow only authenticated administrators to reach them (e.g., using .htaccess or the WordPress capability system).

Generated by OpenCVE AI on October 6, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
Title WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:33.215Z

Reserved: 2026-04-07T10:59:21.050Z

Link: CVE-2026-39796

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:18.839Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:52.697

Modified: 2026-10-06T11:17:26.657

Link: CVE-2026-39796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses