Sensitive Information Exposure in Bogo Plugin for WordPress
CVE-2026-9013
4.3MEDIUM
What is CVE-2026-9013?
The Bogo plugin for WordPress has a vulnerability that enables authenticated attackers with subscriber-level access to extract sensitive information from private, draft, or password-protected posts. By exploiting the bogo_rest_create_post_translation endpoint, these attackers can trigger duplication of posts and access fields containing raw titles, contents, excerpts, and passwords in the default locale. This issue primarily affects posts in non-default locales, as subscriber-level users can bypass permission restrictions by requesting translations into the site's default locale. While the endpoint can be triggered by subscribers, the information can only be effectively read and utilized by those at the Contributor level.
Affected Version(s)
Bogo 0 <= 3.9.1