CVE-2026-92423: Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Meow Gallery WordPress pluginto a version that resolves this vulnerability.Fixed in 5.5.5
Event History
Frequently Asked Questions
Which users can exploit this issue?
An authenticated WordPress user with an Author-level role or higher can exploit it. The issue exposes metadata for draft and private posts belonging to other users.
What information can be disclosed?
The vulnerable functionality can disclose other users' draft and private post titles, authors, dates, and publication statuses. The provided information does not indicate that post content is exposed.
Are sites running version 5.5.5 affected?
No. The issue affects Meow Gallery versions before 5.5.5.