CVE Database /
CVE-2026-9709
CVE
CVE-2026-9709 — Cornerstone [cornerstone] < 7.8.9 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-9709
|
Cornerstone [cornerstone] < 7.8.9 (closed) |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 7.8.9
|
7.8.9 |
2026-06-24 |
—
|
CVE-2026-9709
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings