Sensitive Information Exposure in WP Adminify Plugin for WordPress
CVE-2026-1060

5.3MEDIUM

What is CVE-2026-1060?

The WP Adminify plugin for WordPress is susceptible to sensitive information exposure due to improper access control in its REST API endpoint. Specifically, the endpoint /wp-json/adminify/v1/get-addons-list is set up with a permission callback that does not require authentication, enabling any unauthenticated user to query it. This oversight allows attackers to access a wealth of sensitive data, including a complete list of addons associated with the plugin, their installation status, version numbers, and download URLs. As a result, this vulnerability can significantly compromise the security posture of sites using the affected plugin versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer * <= 4.0.7.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yiğit ibrahim sağlam
.