CVE-2026-10823
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jun 26, 2026
Vendor
unknown
Description
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.