CVE-2026-87848
Received Received - Intake

Unauthenticated Post Data Exposure in MPCX Lightbox WordPress Plugin

Vulnerability report for CVE-2026-87848, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mpcx lightbox From 1.2.2 (inc) to 1.2.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MPCX Lightbox WordPress plugin versions 1.2.2 to 1.2.5 has an unauthenticated non-public post content disclosure vulnerability. It lacks authorization checks on an AJAX action, allowing unauthenticated users to access sensitive post data such as titles, content, or excerpts. This includes private, draft, pending, trashed, and password-protected posts.

Detection Guidance

Check if the MPCX Lightbox plugin versions 1.2.2 to 1.2.5 is installed. Look for unauthenticated requests to the vulnerable AJAX action that may expose post titles, content, or excerpts. Verify if the caption source feature is enabled, as exploitation requires this setting.

Impact Analysis

An attacker could exploit this to retrieve sensitive information from posts that should be restricted. This includes private drafts, password-protected content, or posts marked as pending or trashed. The impact is limited as exploitation requires the plugin's caption source feature to be enabled by an administrator.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR or HIPAA if such data is exposed. Organizations using this plugin may face compliance risks due to potential data breaches.

Mitigation Strategies

Disable the MPCX Lightbox plugin immediately if installed. Ensure the caption source feature is disabled. Monitor for unauthorized access to post data. Check for updates from the plugin developer for a potential fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87848. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart