CVE-2026-78138 UNKNOWN

CVE-2026-78138

Published: 2026-08-27

Description

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…