What is CVE-2026-18943?
The CVE-2026-18943 vulnerability was discovered in the WPC Admin Columns WordPress plugin. In versions prior to 2.3.4, a missing authorisation check in one of its AJAX actions allows users with a role as low as subscriber to read arbitrary user, post, and term metadata, including data belonging to administrators. It is strongly recommended to update the plugin to version 2.3.4 or later immediately.
Azərbaycanca: CVE-2026-18943 zəifliyi WPC Admin Columns WordPress plaginində aşkarlanıb. 2.3.4 versiyasından əvvəlki versiyalarda AJAX əməliyyatlarından birində icazə yoxlaması olmadığı üçün, abunəçi səviyyəsindəki istifadəçilər belə administratorlar da daxil olmaqla ixtiyari istifadəçi, yazı və taksonomiya metadata məlumatlarını oxuya bilər. Plagini dərhal 2.3.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-18943?
The CVE-2026-18943 vulnerability was discovered in the WPC Admin Columns plugin.
To what version should the WPC Admin Columns plugin be updated to protect against CVE-2026-18943?
The WPC Admin Columns plugin should be updated to version 2.3.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.