Junglewise Threat Intelligence

CVE-2026-18943: WPC Admin Columns arbitrary metadata disclosure in AJAX action

CVE-2026-18943 · Severity: medium · CVSS 6.5 · Published 2026-08-12

Executive brief

The WPC Admin Columns WordPress plugin enables site administrators to customize columns in the WordPress admin interface. A flaw in the plugin allows low-privilege users (subscribers) to read sensitive information from any user, post, or term stored in the database—including administrator biographical data, session tokens, and application passwords—through an unprotected AJAX endpoint.

Technical details

The plugin lacks authorization checks on the wpcac_edit_get AJAX action, allowing any authenticated user to request arbitrary user, post, and term metadata. The vulnerability requires a valid WordPress session and nonce (automatically injected into all admin pages), but does not verify that the requesting user has permission to access the target data. An attacker can read sensitive fields such as user session tokens, application passwords, private post metadata, and term metadata by manipulating the uid, id, tid, and field parameters in the AJAX request. The vulnerability has been fixed in version 2.3.4.

Affected products

  • WP Customization WPC Admin Columns before 2.3.4

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Fixed in version 2.3.4

References