Sensitive Information Exposure in 24liveblog Plugin for WordPress
CVE-2026-9183
4.3MEDIUM
What is CVE-2026-9183?
The 24liveblog live blog tool for WordPress is susceptible to a security vulnerability allowing the exposure of sensitive information. This issue arises from the lb24_block_enqueue_scripts() function, which incorrectly processes user permissions, allowing authenticated users with contributor-level access or higher to access sensitive configuration secrets. These include critical tokens and credentials such as the API token and refresh token, which are improperly exposed in the JavaScript context through the lb24BlockData object. Therefore, any user with permission to open the block editor could inspect the page and retrieve this sensitive data, potentially compromising third-party account security.
Affected Version(s)
24liveblog β live blog tool 0 <= 2.2