Dark C0d3rs
HackerOne Disclosed Reports - 2026-09-28 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-09-28 (/Thread-HackerOne-Disclosed-Reports-2026-09-28)



HackerOne disclosed reports - 2026-09-28 - hashXploiter - 09-29-2026

Logo
Medium
resolved

Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relations


Bug reported by Jakub Kozub was disclosed at September 28, 2026, 11:14 am   |   Improper Access Control - Generic

The Secure Custom Fields plugin in version 6.9.2 registered unauthenticated AJAX query handlers for the post_object, relationship, and page_link field types. These handlers ran a WordPress query with the post_status parameter set to "any", which returned draft, pending, private, and future posts without any capability or permission filtering. When these fields were rendered on a public-facing front-end form, the required per-field nonce was emitted into the page HTML. Since the WordPress nonces for logged-out users were shared across all anonymous visitors, any unauthenticated user could reuse the nonce to enumerate non-public post titles and IDs, including through a targeted keyword search.