![]() |
|
HackerOne Disclosed Reports - 2026-09-28 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-09-28 (/Thread-HackerOne-Disclosed-Reports-2026-09-28) |
HackerOne disclosed reports - 2026-09-28 - hashXploiter - 09-29-2026
Medium
resolved Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relationsBug reported by Jakub Kozub was disclosed at September 28, 2026, 11:14 am | Improper Access Control - Generic The Secure Custom Fields plugin in version 6.9.2 registered unauthenticated AJAX query handlers for the post_object, relationship, and page_link field types. These handlers ran a WordPress query with the post_status parameter set to "any", which returned draft, pending, private, and future posts without any capability or permission filtering. When these fields were rendered on a public-facing front-end form, the required per-field nonce was emitted into the page HTML. Since the WordPress nonces for logged-out users were shared across all anonymous visitors, any unauthenticated user could reuse the nonce to enumerate non-public post titles and IDs, including through a targeted keyword search. |