HackerOne Disclosed Reports - 2026-09-28

0 Replies, 12 Views

Logo
Medium
resolved

Unauthenticated disclosure of draft/private/pending post titles & IDs via Secure Custom Fields nopriv AJAX field-query handlers (post_object/relations


Bug reported by Jakub Kozub was disclosed at September 28, 2026, 11:14 am   |   Improper Access Control - Generic

The Secure Custom Fields plugin in version 6.9.2 registered unauthenticated AJAX query handlers for the post_object, relationship, and page_link field types. These handlers ran a WordPress query with the post_status parameter set to "any", which returned draft, pending, private, and future posts without any capability or permission filtering. When these fields were rendered on a public-facing front-end form, the required per-field nonce was emitted into the page HTML. Since the WordPress nonces for logged-out users were shared across all anonymous visitors, any unauthenticated user could reuse the nonce to enumerate non-public post titles and IDs, including through a targeted keyword search.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)