CVE-2026-81348: My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap
Published Sep 5, 2026
·Updated
The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.
Affected Software
1 affected component
WordPress My Private Site<4.2.3
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which sites are exposed?
Sites using My Private Site versions before 4.2.3 are exposed if administrators rely on the plugin's mandatory-login privacy setting to prevent public access to site content.
2
What can an attacker access without logging in?
An unauthenticated user can access post content, comments, and post URLs through affected RSS feeds and sitemap surfaces.
3
Does exploitation require an account or other prior access?
No. The affected surfaces can be accessed by unauthenticated users.