---
id: CVE-2026-87848
title: >-
  The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any
  authorisation or authentication on one of its AJAX actions available to
  unauthenticated users, nor does it check the status of the requested post,
  allowing unauthen…
summary: >-
  The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any
  authorisation or authentication on one of its AJAX actions available to
  unauthenticated users, nor does it check the status of the requested post,
  allowing unauthen…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
product: MPCX Lightbox
affected:
  - mpcx_lightbox >= 1.2.2 <= 1.2.5
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87848'
references:
  - url: 'https://wpscan.com/vulnerability/183ec34f-446f-481f-9019-26e005ad2cfb/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:34:47.454361Z'
ingestedAt: '2026-09-23T10:21:54.380Z'
epss: 0.00202
epssPercentile: 0.08994
---

## Overview

The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
