WPC Admin Columns <= 2.3.3 - Information Exposure to Authenticated (Subscriber+) Arbitrary User/Post/Term Meta Disclosure
medium
The WPC Admin Columns plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.3.3. This is due to missing capability checks before returning term, user, and post meta via AJAX endpoints accessible to any authenticated user. This makes it possible for authenticated attack...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Aug 10, 2026
CVE-2026-18943 on NVD →
WPC Admin Columns 2.0.6 - 2.1.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta Update
high
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_save() function. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 8.8
- Affected:
- 2.0.6 – 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 11, 2025
CVE-2025-3418 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database