Uncovering the ActivityPub Plugin Vulnerability
A significant security flaw has been found in the ActivityPub plugin for WordPress. This issue, tracked as CVE-2026-4338, could allow anyone to view sensitive content on your website without needing to log in. This includes posts that are still in draft, scheduled for future publication, or awaiting review. For websites using the ActivityPub plugin, this means private information intended only for internal eyes or future release could be exposed to the public.
CVE Details
Product: ActivityPub WordPress Plugin
Published: April 8, 2026
Severity: High
Status: Analyzed
Affected Products
This vulnerability affects all versions of the ActivityPub WordPress plugin prior to 8.0.2. If you are running any version older than 8.0.2, your website is at risk.
Current Status
The vulnerability has been thoroughly analyzed, and a fix has been released by the developers. It is crucial for all users to update their plugin to ensure their websites remain secure.
Severity Level
The CVSS score for this vulnerability is 7.5, which is classified as a High severity. This rating indicates that the flaw is serious, primarily because it leads to Sensitive Data Disclosure (CWE-200). An attacker doesn’t need any special permissions to exploit this, making it a significant threat to your content’s privacy.
Possible Solutions
The most important step you can take to protect your WordPress site is to update the ActivityPub plugin immediately. Ensure you are running version 8.0.2 or newer. Always back up your website before performing any updates to prevent data loss.
References
https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/


