CVE-2026-81348 PUBLISHED

My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap

Assigner: WPScan
Reserved: 26.08.2026 Published: 05.09.2026 Updated: 05.09.2026

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.

Product Status

Vendor Unknown
Product My Private Site
Versions Default: unaffected
  • affected from 0 to 4.2.3 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE