CVE-2026-10823: Unknown Ymc Filter
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.
Affected products
- Unknown Ymc Filter: before 3.11.3 (fixed in 3.11.3)
Published 2026-06-26. Last modified 2026-06-26.