Executive brief
The ActivityPub plugin for WordPress, which allows websites to connect with federated social networks, contains a security flaw that exposes private content. This vulnerability allows anyone on the internet to view draft, scheduled, or pending blog posts without needing to log in. This could lead to the premature disclosure of sensitive information, embargoed news, or internal communications before they are intended for public release.
Technical details
An information disclosure vulnerability exists in the ActivityPub WordPress plugin due to insufficient filtering of post statuses during content retrieval. By appending specific query parameters (such as activitypub=1 and preview=1) to a request for a specific post ID, an unauthenticated remote attacker can bypass standard visibility checks. This allows for the unauthorized viewing of posts that are currently in draft, scheduled, or pending states. The issue is resolved in version 8.0.2.
Affected products
- Automattic ActivityPub < 8.0.2
Timeline
- 2026-03-18: disclosed: Publicly published via WPScan
- 2026-04-08: advisory: NVD entry published
- 2026-04-08: patched: Fixed in version 8.0.2