CVE-2026-4338 is an authentication bypass vulnerability affecting the ActivityPub WordPress plugin versions prior to 8.0.2, where improper post filtering allows unauthenticated users to access draft, scheduled, and pending posts that should remain restricted. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, resulting in high confidentiality impact through unauthorized information disclosure. Current exploitation appears limited, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows minimal community attention with an inactive status on threat tracking lists. The EPSS score of 0.00057 indicates relatively low probability of exploitation in the wild compared to other CVEs, suggesting the threat landscape has not yet focused attention on this particular flaw. Users of the ActivityPub plugin should prioritize updating to version 8.0.2 or later to remediate this information disclosure risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0.2CPE matchmatch criteria | cpe:2.3:a:automattic:activitypub:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.