LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-7459

Published
CVSS7.5
Severityhigh
WeaknessCWE-640
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and does not enforce the per-logger capability checks normally applied by Log_Query. As a result, a Subscriber-level user can POST to /wp-json/simple-history/v1/events/<id>/react with the _fields=context query parameter and read the full context of any Simple History event — including SimpleUserLogger entr

References

← Back to the CVE Tracker

Our coverage of CVE-2026-7459

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-7459.