resolved
Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relations
Bug reported by Jakub Kozub was disclosed at September 28, 2026, 11:14 am | Improper Access Control - Generic
The Secure Custom Fields plugin in version 6.9.2 registered unauthenticated AJAX query handlers for the post_object, relationship, and page_link field types. These handlers ran a WordPress query with the post_status parameter set to "any", which returned draft, pending, private, and future posts without any capability or permission filtering. When these fields were rendered on a public-facing front-end form, the required per-field nonce was emitted into the page HTML. Since the WordPress nonces for logged-out users were shared across all anonymous visitors, any unauthenticated user could reuse the nonce to enumerate non-public post titles and IDs, including through a targeted keyword search.

