WordPress Plugin Vulnerabilities

YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure

Description

The plugin does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.

Proof of Concept

Affects Plugins

Fixed in 3.11.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Ahmed Hashim Ismael
Submitter
Ahmed Hashim Ismael
Verified
Yes

Timeline

Publicly Published
2026-06-05 (about 21 days ago)
Added
2026-06-05 (about 20 days ago)
Last Updated
2026-06-25 (about 9 hours ago)

Other