CVE-2026-78138: Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Finale Lite (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.21.0 - Compensating control
Restrict access to the WordPress AJAX endpoint used by wcct_quick_view_html to trusted users/roles (since any authenticated Subscriber+ can read campaign configuration data before 2.21.0).
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with Subscriber-level access or higher can exploit the affected AJAX action. No elevated WordPress capability is required.
What information can be disclosed?
An attacker can retrieve Finale Lite sales-campaign configuration and scheduling data for an arbitrary post ID.
Which installations are affected?
Finale Lite versions before 2.21.0 are affected. The issue is exposed through the wcct_quick_view_html AJAX action.