Skip to content
CVE-2026-92423: Meow Gallery Information Disclosure (CVSS 2.7)

CVE-2026-92423: Meow Gallery Information Disclosure (CVSS 2.7)

Strix.Ai September 20, 2026

CVE-2026-92423 is a low-severity vulnerability rated 2.7/10 on the CVSS scale . The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts. .

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Source: CNA advisory (CVE.org). NVD analysis pending.

Frequently Asked Questions

How Strix found a critical auth bypass in etcd Strix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.

Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.

PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.

AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.

Related CVEs from 2026

CVE-2026-92417 A vulnerability was found in Open5GS up to 2.8.0. This affec… 6.5

CVE-2026-92418 A vulnerability was determined in ChangeWeDer crm up to c07b… 3.5

CVE-2026-9242 The RegistrationMagic – Custom Registration Forms, User Regi… 5.3

CVE-2026-92420 The Hydra Booking — Appointment Scheduling & Booking Calenda… 3.8

CVE-2026-92421 The Hydra Booking — Appointment Scheduling & Booking Calenda… 4.7

CVE-2026-92422 The Meow Gallery WordPress plugin before 5.5.5 does not prop… 6.5

CVE-2026-92425 The Hydra Booking — Appointment Scheduling & Booking Calenda… 5.5

CVE-2026-9243 The Plus Addons for Elementor plugin for WordPress is vulner… 6.4

CVE-2026-92430 The Rede Itaú for WooCommerce — Payment PIX, Credit Card and… 5.3

CVE-2026-92435 The Mailchimp for WooCommerce WordPress plugin before 6.1.1 … 5.3

CVE-2026-9244 Rejected reason: This CVE ID has been rejected or withdrawn …

CVE-2026-9245 Improper input validation in the external authentication pro… 5

Are you affected by CVE-2026-92423 ?

Run a free Strix scan to check your systems for this vulnerability.