{"api_version":"1","generated_at":"2026-09-05T09:12:51+00:00","cve":"CVE-2026-78150","urls":{"html":"https://cve.report/CVE-2026-78150","api":"https://cve.report/api/cve/CVE-2026-78150.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78150","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78150"},"summary":{"title":"Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR","description":"The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-05 07:17:12","updated_at":"2026-09-05 07:17:12"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/e6c8a115-88a2-4fdf-9b97-8ae8a8c7f0aa/","name":"https://wpscan.com/vulnerability/e6c8a115-88a2-4fdf-9b97-8ae8a8c7f0aa/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78150","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78150","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Smart Post","version":"affected 4.0.0 4.0.8 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Revanth Hari Narayana Matte","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Smart Post","vendor":"Unknown","versions":[{"lessThan":"4.0.8","status":"affected","version":"4.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Revanth Hari Narayana Matte"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-05T06:00:05.474Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/e6c8a115-88a2-4fdf-9b97-8ae8a8c7f0aa/"}],"source":{"discovery":"EXTERNAL"},"title":"Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-78150","datePublished":"2026-09-05T06:00:05.474Z","dateReserved":"2026-08-23T06:57:58.712Z","dateUpdated":"2026-09-05T06:00:05.474Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-05 07:17:12","lastModifiedDate":"2026-09-05 07:17:12","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78150","Ordinal":"1","Title":"Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected","CVE":"CVE-2026-78150","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78150","Ordinal":"1","NoteData":"The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.","Type":"Description","Title":"Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected"}]}}}