CVE-2026-4338: ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
Published Apr 8, 2026
·Updated
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
Affected Software
2 affected components
wordpress/activitypub<8.0.2
Automattic Activitypub Wordpress<8.0.2
Event History
Apr 8, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-4338?
CVE-2026-4338 has a severity score of high, rated at 7.5 on the CVSS scale.
2
How do I fix CVE-2026-4338?
To fix CVE-2026-4338, you should update the ActivityPub WordPress plugin to version 8.0.2 or later.
3
What kind of exposure does CVE-2026-4338 have?
CVE-2026-4338 allows unauthenticated users to access drafts, scheduled, and pending posts.
4
Which plugin is affected by CVE-2026-4338?
CVE-2026-4338 affects the ActivityPub plugin for WordPress prior to version 8.0.2.
5
When was CVE-2026-4338 published?
CVE-2026-4338 was published on April 8, 2026.