CVE-2026-92548: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in hcabrera WP Popular Posts
The WP Popular Posts WordPress plugin up to version 7.4.2 has a vulnerability that allows unauthenticated attackers to access sensitive information from non-public post objects via the 'context' parameter in its REST API. This occurs because the plugin's REST route does not enforce permission checks and improperly passes the context parameter to WordPress core functions, exposing fields like raw title, content, password, meta, status, and guid that should not be publicly accessible.
AI Analysis
Technical Summary
CVE-2026-92548 describes a sensitive information exposure vulnerability in the WP Popular Posts plugin for WordPress versions up to and including 7.4.2. The flaw arises because the plugin registers a REST API route with a permission callback that always returns true, allowing unauthenticated access. The 'context' parameter supplied by the caller is passed directly to WP_REST_Posts_Controller::prepare_item_for_response() without permission checks, enabling extraction of sensitive edit-context fields from non-public post types such as wp_block synced patterns. Additionally, the underlying query accepts arbitrary post_type values without enforcing public or show_in_rest visibility flags, further broadening the exposure.
Potential Impact
An unauthenticated attacker can retrieve sensitive information from non-public WordPress post objects, including raw titles, content bodies, passwords, metadata, status, and GUIDs. This exposure could lead to information disclosure that WordPress core itself prevents for unauthenticated users. However, there is no indication of integrity or availability impact, and no known exploits are reported in the wild.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Users should monitor the vendor's advisory channels for updates. Until a fix is available, restricting access to the REST API endpoints or disabling the WP Popular Posts plugin may reduce exposure. Applying strict access controls on the WordPress REST API and limiting unauthenticated access to sensitive endpoints is recommended.
CVE-2026-92548: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in hcabrera WP Popular Posts
Description
The WP Popular Posts WordPress plugin up to version 7.4.2 has a vulnerability that allows unauthenticated attackers to access sensitive information from non-public post objects via the 'context' parameter in its REST API. This occurs because the plugin's REST route does not enforce permission checks and improperly passes the context parameter to WordPress core functions, exposing fields like raw title, content, password, meta, status, and guid that should not be publicly accessible.
CVSS v3.1
Score 5.3medium
Affected software
hcabrera
WP Popular Posts
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92548 describes a sensitive information exposure vulnerability in the WP Popular Posts plugin for WordPress versions up to and including 7.4.2. The flaw arises because the plugin registers a REST API route with a permission callback that always returns true, allowing unauthenticated access. The 'context' parameter supplied by the caller is passed directly to WP_REST_Posts_Controller::prepare_item_for_response() without permission checks, enabling extraction of sensitive edit-context fields from non-public post types such as wp_block synced patterns. Additionally, the underlying query accepts arbitrary post_type values without enforcing public or show_in_rest visibility flags, further broadening the exposure.
Potential Impact
An unauthenticated attacker can retrieve sensitive information from non-public WordPress post objects, including raw titles, content bodies, passwords, metadata, status, and GUIDs. This exposure could lead to information disclosure that WordPress core itself prevents for unauthenticated users. However, there is no indication of integrity or availability impact, and no known exploits are reported in the wild.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Users should monitor the vendor's advisory channels for updates. Until a fix is available, restricting access to the REST API endpoints or disabling the WP Popular Posts plugin may reduce exposure. Applying strict access controls on the WordPress REST API and limiting unauthenticated access to sensitive endpoints is recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-16T13:02:25.542Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abde6202a4e24523d5e1cfe
Added to database: 10/01/2026, 04:48:32 UTC
Last enriched: 10/01/2026, 05:03:04 UTC
Last updated: 10/01/2026, 05:05:15 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.