CVE-2026-18943: WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure
Published Aug 12, 2026
·Updated
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.
Affected Software
1 affected component
WPClever WPC Admin Columns<2.3.4
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-18943?
The severity of CVE-2026-18943 is rated at risk level 54.
2
What does CVE-2026-18943 affect?
CVE-2026-18943 affects the WPC Admin Columns WordPress plugin versions before 2.3.4.
3
How do I fix CVE-2026-18943?
To fix CVE-2026-18943, update the WPC Admin Columns plugin to version 2.3.4 or later.
4
Who is vulnerable to CVE-2026-18943?
Users with the subscriber role are vulnerable to CVE-2026-18943 due to inadequate authorization checks.
5
What type of data is disclosed in CVE-2026-18943?
CVE-2026-18943 allows disclosure of arbitrary user, post, and term metadata, potentially including sensitive data from administrators.