CVE-2026-15231 - TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
CVE ID :CVE-2026-15231
Published : Aug. 3, 2026, 6 a.m. | 53 minutes ago
Description :The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 3, 2026, 6 a.m. | 53 minutes ago
Description :The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...