Retour à la veille

CVE-2026-19699

Publié : 20 août 2026
Modifié : 20 août 2026
Lien officiel NVD

Description détaillée

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.

Références et Patchs