What is CVE-2026-12124?
CVE-2026-12124 is identified in the PDFDraft plugin for WordPress. This vulnerability allows unauthorized data access due to a missing capability check on the `serveTemplatePdfAjax()` function and the `serveTemplatePdf()` REST route. Users of the plugin are strongly advised to apply the emergency update.
Azərbaycanca: CVE-2026-12124 WordPress üçün PDFDraft plaginində müəyyən edilib. Bu boşluq `serveTemplatePdfAjax()` funksiyası və `serveTemplatePdf()` REST marşrutunda yetkinlik yoxlamasının olmaması səbəbindən icazəsiz məlumat əldə etməyə imkan verir. Plugin istifadəçilərinə təcili yeniləmə tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which WordPress plugin has CVE-2026-12124 been discovered?
This vulnerability has been identified in the PDFDraft plugin for WordPress.
How can I protect against CVE-2026-12124?
Users are strongly advised to apply the emergency update immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.