Description
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.
Weaknesses
- — CWE-200 Information Exposure
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | YMC Filter | 0 to <3.11.3 |
References
- https://wpscan.com/vulnerability/b55ebf9e-a05d-4ae4-b653-da7db63e76d2/ (exploit vdb-entry technical-description)
Generated from the official CVE List on 26 Jun 2026 07:05 UTC.