Executive brief
The Tribal plugin for WordPress, used for community or tribal management features, contains a security flaw that exposes sensitive information. An unauthorized person could access data that is intended to be private or restricted, potentially leading to further attacks or privacy breaches. This issue affects all versions up to and including 1.3.4.
Technical details
The Tribal plugin (the-tech-tribe) for WordPress is vulnerable to CWE-201 (Insertion of Sensitive Information Into Sent Data). The flaw allows an unauthenticated remote attacker to retrieve sensitive data that is inadvertently embedded or included in data sent by the application. This is a sensitive data exposure vulnerability where the application does not properly filter or restrict the output of private information. The issue is resolved in version 1.3.5.
Affected products
- thetechtribe The Tribal <= 1.3.4
Timeline
- 2026-01-31: other: Reported by Nabil Irawan
- 2026-03-02: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published
- 2026-03-02: patched: Version 1.3.5 released to address the vulnerability