CVE-2026-4338
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts
CVSS
7.5
High
EPSS
0.4%
p36
KEV
—
Exploit Today
11
0-100
Published: Apr 8, 2026 · Last modified: Jul 24, 2026
0.4%EPSS · 30 days0.4%
2026-08-272026-09-25
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
No related CVEs by CWE or product.