Sensitive Information Exposure in WP Adminify Plugin for WordPress
CVE-2026-1060
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 January 2026
What is CVE-2026-1060?
The WP Adminify plugin for WordPress is susceptible to sensitive information exposure due to improper access control in its REST API endpoint. Specifically, the endpoint /wp-json/adminify/v1/get-addons-list is set up with a permission callback that does not require authentication, enabling any unauthenticated user to query it. This oversight allows attackers to access a wealth of sensitive data, including a complete list of addons associated with the plugin, their installation status, version numbers, and download URLs. As a result, this vulnerability can significantly compromise the security posture of sites using the affected plugin versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer * <= 4.0.7.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved