Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-09-28
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relations


Bug reported by Jakub Kozub was disclosed at September 28, 2026, 11:14 am   |   Improper Access Control - Generic

The Secure Custom Fields plugin in version 6.9.2 registered unauthenticated AJAX query handlers for the post_object, relationship, and page_link field types. These handlers ran a WordPress query with the post_status parameter set to "any", which returned draft, pending, private, and future posts without any capability or permission filtering. When these fields were rendered on a public-facing front-end form, the required per-field nonce was emitted into the page HTML. Since the WordPress nonces for logged-out users were shared across all anonymous visitors, any unauthenticated user could reuse the nonce to enumerate non-public post titles and IDs, including through a targeted keyword search.