Executive brief
The Adminify WordPress plugin, which is used to customize and manage the WordPress dashboard, contains a security flaw in its search feature. This vulnerability allows low-privileged users, such as guest contributors, to view sensitive information they should not have access to. This includes private post titles, unpublished comments, the site's list of installed plugins, and user account names, potentially aiding further targeted attacks.
Technical details
An information disclosure vulnerability exists in the Adminify WordPress plugin before version 4.2.10 due to missing per-user read-capability checks in the 'pxlbsadminify_all_search' AJAX action. An authenticated attacker with a low-privilege role (such as Contributor) can obtain a valid security nonce from the admin dashboard and execute a crafted AJAX request. This allows the attacker to bypass standard WordPress core permission restrictions to view sensitive data, including unpublished post titles, pending comments, the site's plugin inventory, and user account names. The issue is resolved in version 4.2.10.
Affected products
- Adminify Adminify < 4.2.10
Timeline
- 2026-06-11: disclosed: Publicly published by WPScan
- 2026-07-02: advisory: NVD publication date
- 2026-04-21: patched: Fixed in version 4.2.10