sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-09-08

Smart Post - Security Vulnerability (CVE-2026-78149)

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.

PLUGIN Smart Post

CVE-2026-78149

MEDIUM CVSS 5.3 2026-09-05
Threat Entry Updated 2026-09-08

Smart Post - Security Vulnerability (CVE-2026-78150)

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.

PLUGIN Smart Post

CVE-2026-78150

LOW CVSS 2.7 2026-09-05