Sensitive Information Exposure in Bogo Plugin for WordPress
CVE-2026-9013

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-9013?

The Bogo plugin for WordPress has a vulnerability that enables authenticated attackers with subscriber-level access to extract sensitive information from private, draft, or password-protected posts. By exploiting the bogo_rest_create_post_translation endpoint, these attackers can trigger duplication of posts and access fields containing raw titles, contents, excerpts, and passwords in the default locale. This issue primarily affects posts in non-default locales, as subscriber-level users can bypass permission restrictions by requesting translations into the site's default locale. While the endpoint can be triggered by subscribers, the information can only be effectively read and utilized by those at the Contributor level.

Affected Version(s)

Bogo 0 <= 3.9.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Lacambra
.