CVE

CVE-2026-9709 — Cornerstone [cornerstone] < 7.8.9 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9709 Cornerstone [cornerstone] < 7.8.9 (closed) Exposure of Sensitive Information to an Unauthorized Actor Unknown < 7.8.9 7.8.9 2026-06-24

CVE-2026-9709

Prior to version 7.8.9, a vulnerability in the Cornerstone plugin's REST API exposed user metadata to authenticated users, including roles and session token previews, as well as billing and shipping information. This issue specifically affected the premium page builder distributed with X, but not the standalone free Cornerstone plugin on WordPress.org. The bug was present in versions prior to 7.8.9.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.