{"id":"CVE-2026-92423","title":"The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above …","summary":"The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above …","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"product":"Meow Gallery","affected":["meow_gallery < 5.5.5"],"published":"2026-09-20","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:34:57.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92423","references":[{"url":"https://wpscan.com/vulnerability/03bd9795-8036-4ec9-ab11-8dc2059d4245/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00189,"epssPercentile":0.08759,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-20T13:51:14.501667Z"},"ingestedAt":"2026-09-20T07:16:12.217Z","slug":"CVE-2026-92423","body":"## Overview\n\nThe Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208031,"id":"CVE-2026-92423","ts":1789914180600,"field":"cvss","old":null,"new":"2.7"},{"seq":208030,"id":"CVE-2026-92423","ts":1789914180600,"field":"severity","old":"none","new":"low"}]}