PoC Index

CVE-2026-78138

MEDIUM 4.3EPSS 0.2%

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.18% chance of exploitation in the next 30 days, 7th percentile
Published
2026-08-27

Proof-of-concept exploits (1)

References

Related