The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones. | |
| Title | MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:49:00.879Z
Reserved: 2026-09-09T11:31:38.909Z
Link: CVE-2026-87848
Updated: 2026-09-23T10:33:23.995Z
Status : Received
Published: 2026-09-23T11:17:15.750
Modified: 2026-09-23T11:17:15.750
Link: CVE-2026-87848
No data.
OpenCVE Enrichment
No data.
Weaknesses