Skip to main content
Vulnerability Database/CVE-2026-87848

CVE-2026-87848: MPCX Lightbox WordPress Plugin Disclosure

CVE-2026-87848 is an information disclosure vulnerability in MPCX Lightbox WordPress plugin versions 1.2.2 through 1.2.5 that allows unauthorized access to private post content. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-87848 Overview

CVE-2026-87848 is a missing authorization vulnerability in the MPCX Lightbox WordPress plugin, versions 1.2.2 through 1.2.5. The plugin exposes an AJAX action to unauthenticated users without any authorization checks or post-status validation. Attackers can retrieve the title, content, or excerpt of arbitrary posts, including private, draft, pending, trashed, and password-protected posts. The flaw is categorized under [CWE-862] (Missing Authorization).

Critical Impact

Unauthenticated remote attackers can disclose the contents of non-public WordPress posts, exposing draft, private, and password-protected material.

Affected Products

  • MPCX Lightbox WordPress plugin version 1.2.2
  • MPCX Lightbox WordPress plugin versions 1.2.3 and 1.2.4
  • MPCX Lightbox WordPress plugin version 1.2.5

Discovery Timeline

  • 2026-09-23 - CVE-2026-87848 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-87848

Vulnerability Analysis

The MPCX Lightbox plugin registers an AJAX action reachable by unauthenticated visitors through the standard wp-admin/admin-ajax.php endpoint. The handler accepts a post identifier from the request and returns post fields directly, without verifying the caller's capabilities or the post's publication status.

WordPress exposes AJAX callbacks registered via wp_ajax_nopriv_{action} to any visitor. When such a callback returns post data, the plugin is expected to enforce access checks using functions such as current_user_can() or by validating the post status. MPCX Lightbox performs neither check.

The outcome is disclosure of title, content, and excerpt fields for any post ID an attacker enumerates, including material protected by WordPress access controls. Refer to the WPScan Vulnerability Report for the technical write-up.

Root Cause

The root cause is missing authorization on an AJAX handler. The plugin does not authenticate the requester, does not verify a nonce tied to a privileged action, and does not check whether the requested post is publicly viewable. Password-protected posts are returned without prompting for the password.

Attack Vector

Exploitation requires only network access to the WordPress site. An attacker sends a crafted HTTP POST request to admin-ajax.php, specifying the vulnerable action name and a target post ID. The server responds with the requested post fields. Attackers can iterate through post IDs to enumerate hidden content.

// No verified proof-of-concept code is published for this issue.
// See the WPScan advisory for reproduction details.

Detection Methods for CVE-2026-87848

Indicators of Compromise

  • Repeated unauthenticated POST requests to /wp-admin/admin-ajax.php referencing the MPCX Lightbox AJAX action name
  • Sequential or scripted enumeration of the post_id parameter from a single source IP
  • Access log entries showing admin-ajax.php responses with non-empty bodies for post IDs that are not published

Detection Strategies

  • Inspect web server logs for high-volume admin-ajax.php traffic originating from unauthenticated sessions
  • Correlate AJAX request patterns with the plugin's known action names to identify targeted probing
  • Alert when a single client requests many distinct post_id values in a short window

Monitoring Recommendations

  • Enable verbose logging on the WordPress instance and forward it to a centralized analytics platform
  • Track outbound response sizes from admin-ajax.php to identify bulk content disclosure
  • Monitor plugin inventory to detect any installations of MPCX Lightbox in the vulnerable version range

How to Mitigate CVE-2026-87848

Immediate Actions Required

  • Identify WordPress sites running MPCX Lightbox versions 1.2.2 through 1.2.5
  • Deactivate the plugin until a fixed version is confirmed available and installed
  • Review access logs for evidence of prior enumeration against admin-ajax.php
  • Rotate any secrets or sensitive information that may have been stored in draft or private posts

Patch Information

No fixed version is listed in the CVE record at publication. Consult the WPScan Vulnerability Report and the plugin vendor's changelog for updated patch status before re-enabling the plugin.

Workarounds

  • Disable or uninstall the MPCX Lightbox plugin on affected sites
  • Restrict access to wp-admin/admin-ajax.php at the web application firewall for the vulnerable action name
  • Move sensitive content out of draft, pending, or password-protected posts until the plugin is patched or removed
bash
# Example: block requests to the vulnerable AJAX action at the web server
# Replace <action_name> with the plugin's AJAX action string from the advisory
location = /wp-admin/admin-ajax.php {
    if ($arg_action = "<action_name>") {
        return 403;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.