Exposure of Sensitive Metadata in Cornerstone Page Builder by X Company
CVE-2026-9710
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 June 2026
Badges
What is CVE-2026-9710?
The Cornerstone Page Builder plugin for WordPress prior to version 7.8.8 has a significant vulnerability due to a lack of enforced capability checks on a specific CSS-preview request handler. This flaw permits any logged-in user to access the nonce required for making requests, making it possible for them to evaluate dynamic content tokens against any user account. As a result, sensitive metadata, including raw password hashes, can be disclosed, posing a significant risk to user privacy and site security. This issue exclusively affects the premium version of the Cornerstone plugin offered as part of the X theme, not the separate free version available on the .org repository.
Affected Version(s)
Cornerstone 3.0.0 < 7.8.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.