Executive brief
The Context Blog theme for WordPress contains a security flaw that allows unauthorized individuals to view content that is supposed to be password-protected. This means that private or sensitive blog posts intended for a restricted audience could be read by anyone on the internet. The issue affects all versions of the theme up to 1.3.5.
Technical details
The Context Blog theme for WordPress is vulnerable to sensitive information exposure (CWE-200) due to improper access controls within the 'context_blog_modal_popup' component. An unauthenticated remote attacker can exploit this flaw to bypass password protections on specific posts and retrieve their full content. The vulnerability exists in all versions up to and including 1.3.5. A changeset indicates that a fix has been developed to address the improper handling of protected content within the modal popup functionality.
Affected products
- postmagthemes Context Blog up to, and including, 1.3.5
Timeline
- 2026-07-11: disclosed
- 2026-07-11: advisory