CVE-2026-92423
LOW
NVD
CVSS Score
2.7
Severity
LOW
Published
Sep 20, 2026
Vendor
unknown
Description
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.