ActivityPub WordPress Plugin Information Disclosure Vulnerability (CVE-2026-4338) — High Severity

Uncovering the ActivityPub Plugin Vulnerability

A significant security flaw has been found in the ActivityPub plugin for WordPress. This issue, tracked as CVE-2026-4338, could allow anyone to view sensitive content on your website without needing to log in. This includes posts that are still in draft, scheduled for future publication, or awaiting review. For websites using the ActivityPub plugin, this means private information intended only for internal eyes or future release could be exposed to the public.

CVE Details

Product: ActivityPub WordPress Plugin
Published: April 8, 2026
Severity: High
Status: Analyzed

Affected Products

This vulnerability affects all versions of the ActivityPub WordPress plugin prior to 8.0.2. If you are running any version older than 8.0.2, your website is at risk.

Current Status

The vulnerability has been thoroughly analyzed, and a fix has been released by the developers. It is crucial for all users to update their plugin to ensure their websites remain secure.

Severity Level

The CVSS score for this vulnerability is 7.5, which is classified as a High severity. This rating indicates that the flaw is serious, primarily because it leads to Sensitive Data Disclosure (CWE-200). An attacker doesn’t need any special permissions to exploit this, making it a significant threat to your content’s privacy.

Possible Solutions

The most important step you can take to protect your WordPress site is to update the ActivityPub plugin immediately. Ensure you are running version 8.0.2 or newer. Always back up your website before performing any updates to prevent data loss.

References

https://wpscan.com/vulnerability/50f68395-72fc-4f99-8e6d-6aa90cc640b5/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.