CVE-2026-87848 Overview
CVE-2026-87848 is a missing authorization vulnerability in the MPCX Lightbox WordPress plugin, versions 1.2.2 through 1.2.5. The plugin exposes an AJAX action to unauthenticated users without any authorization checks or post-status validation. Attackers can retrieve the title, content, or excerpt of arbitrary posts, including private, draft, pending, trashed, and password-protected posts. The flaw is categorized under [CWE-862] (Missing Authorization).
Critical Impact
Unauthenticated remote attackers can disclose the contents of non-public WordPress posts, exposing draft, private, and password-protected material.
Affected Products
- MPCX Lightbox WordPress plugin version 1.2.2
- MPCX Lightbox WordPress plugin versions 1.2.3 and 1.2.4
- MPCX Lightbox WordPress plugin version 1.2.5
Discovery Timeline
- 2026-09-23 - CVE-2026-87848 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-87848
Vulnerability Analysis
The MPCX Lightbox plugin registers an AJAX action reachable by unauthenticated visitors through the standard wp-admin/admin-ajax.php endpoint. The handler accepts a post identifier from the request and returns post fields directly, without verifying the caller's capabilities or the post's publication status.
WordPress exposes AJAX callbacks registered via wp_ajax_nopriv_{action} to any visitor. When such a callback returns post data, the plugin is expected to enforce access checks using functions such as current_user_can() or by validating the post status. MPCX Lightbox performs neither check.
The outcome is disclosure of title, content, and excerpt fields for any post ID an attacker enumerates, including material protected by WordPress access controls. Refer to the WPScan Vulnerability Report for the technical write-up.
Root Cause
The root cause is missing authorization on an AJAX handler. The plugin does not authenticate the requester, does not verify a nonce tied to a privileged action, and does not check whether the requested post is publicly viewable. Password-protected posts are returned without prompting for the password.
Attack Vector
Exploitation requires only network access to the WordPress site. An attacker sends a crafted HTTP POST request to admin-ajax.php, specifying the vulnerable action name and a target post ID. The server responds with the requested post fields. Attackers can iterate through post IDs to enumerate hidden content.
// No verified proof-of-concept code is published for this issue.
// See the WPScan advisory for reproduction details.
Detection Methods for CVE-2026-87848
Indicators of Compromise
- Repeated unauthenticated POST requests to /wp-admin/admin-ajax.php referencing the MPCX Lightbox AJAX action name
- Sequential or scripted enumeration of the post_id parameter from a single source IP
- Access log entries showing admin-ajax.php responses with non-empty bodies for post IDs that are not published
Detection Strategies
- Inspect web server logs for high-volume admin-ajax.php traffic originating from unauthenticated sessions
- Correlate AJAX request patterns with the plugin's known action names to identify targeted probing
- Alert when a single client requests many distinct post_id values in a short window
Monitoring Recommendations
- Enable verbose logging on the WordPress instance and forward it to a centralized analytics platform
- Track outbound response sizes from admin-ajax.php to identify bulk content disclosure
- Monitor plugin inventory to detect any installations of MPCX Lightbox in the vulnerable version range
How to Mitigate CVE-2026-87848
Immediate Actions Required
- Identify WordPress sites running MPCX Lightbox versions 1.2.2 through 1.2.5
- Deactivate the plugin until a fixed version is confirmed available and installed
- Review access logs for evidence of prior enumeration against admin-ajax.php
- Rotate any secrets or sensitive information that may have been stored in draft or private posts
Patch Information
No fixed version is listed in the CVE record at publication. Consult the WPScan Vulnerability Report and the plugin vendor's changelog for updated patch status before re-enabling the plugin.
Workarounds
- Disable or uninstall the MPCX Lightbox plugin on affected sites
- Restrict access to wp-admin/admin-ajax.php at the web application firewall for the vulnerable action name
- Move sensitive content out of draft, pending, or password-protected posts until the plugin is patched or removed
# Example: block requests to the vulnerable AJAX action at the web server
# Replace <action_name> with the plugin's AJAX action string from the advisory
location = /wp-admin/admin-ajax.php {
if ($arg_action = "<action_name>") {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
