Exposure of Sensitive Metadata in Cornerstone Page Builder by X Company
CVE-2026-9710

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-9710?

The Cornerstone Page Builder plugin for WordPress prior to version 7.8.8 has a significant vulnerability due to a lack of enforced capability checks on a specific CSS-preview request handler. This flaw permits any logged-in user to access the nonce required for making requests, making it possible for them to evaluate dynamic content tokens against any user account. As a result, sensitive metadata, including raw password hashes, can be disclosed, posing a significant risk to user privacy and site security. This issue exclusively affects the premium version of the Cornerstone plugin offered as part of the X theme, not the separate free version available on the .org repository.

Affected Version(s)

Cornerstone 3.0.0 < 7.8.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Real_King_Engine (ISAL FRAMEWORK)
WPScan
.