Sceawere
Vulnerability Detail
CVE-2026-39796UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Access Control Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- Flipper Code – WordPress Development…
- Product
- Advanced Posts Listing – Show Post List Easily
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:52.697Z",
"pubdate": "2026-10-06T09:17:52.697Z",
"executiveSummary": "Advanced Posts Listing – Show Post List Easily versions 1.0.8 and earlier contain a critical broken access control vulnerability. This flaw permits unauthenticated remote attackers to perform unauthorized actions or access restricted data within the plugin's scope. The vulnerability stems from insufficient validation of user privileges and inadequate access control checks on sensitive endpoints. Because this is an unauthenticated vulnerability, an attacker does not require a legitimate account or administrative rights to trigger the flaw, posing a significant risk to site integrity and data confidentiality. The impact includes potential information disclosure or unauthorized administrative operations, depending on the specific functionality exposed through the vulnerable endpoint. Given the ease of exploitation, this vulnerability presents a high risk to WordPress installations relying on this plugin for dynamic content management. Users are exposed to unauthorized system interactions without the need for prior authentication, necessitating immediate remediation or the implementation of compensating security controls until a patch is available.",
"technicalDetails": "The vulnerability resides within the core functionality of the Advanced Posts Listing – Show Post List Easily plugin, specifically affecting versions 1.0.8 and earlier. The primary root cause is the lack of proper capability checks (e.g., current_user_can()) or nonces (number used once) when handling requests to the plugin’s AJAX or API endpoints. In the WordPress environment, plugins often register internal endpoints to retrieve post metadata or dynamic content; if these endpoints fail to verify the authorization level of the request initiator, they become susceptible to broken access control.\nThe attack flow initiates when an unauthenticated remote attacker identifies the exposed endpoint, typically via static analysis of the plugin's JavaScript files or PHP source code. By crafting a specific HTTP GET or POST request targeting these unprotected backend functions, the attacker can bypass the intended authorization logic. Since the backend handler does not validate if the requester possesses the required administrative or editor privileges, it processes the request as if it were a legitimate administrative operation.\nThe exploitation mechanism allows an attacker to manipulate or extract content that would otherwise be restricted. If the vulnerable function interacts with the database to display or edit post lists, the attacker may be able to force the application to return sensitive post queries or execute administrative actions by manipulating the request parameters. Because the vulnerability requires no authentication, the network exposure is broad, as any user capable of reaching the web server can attempt to trigger the vulnerable code path.\nPost-exploitation impact varies based on the plugin's internal capabilities. If the affected component supports content modifications, the attacker might be able to alter post statuses, delete content, or extract unpublished (draft) post data, leading to severe information disclosure and integrity compromise. The lack of strict sanitization combined with the absence of access controls turns a standard utility function into an entry point for unauthorized administrative manipulation."
}