CVE Database /
CVE-2026-9710
CVE
CVE-2026-9710 — Cornerstone [cornerstone] < 7.8.8 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-9710
|
Cornerstone [cornerstone] < 7.8.8 (closed) |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 7.8.8
|
7.8.8 |
2026-06-24 |
—
|
CVE-2026-9710
Prior to version 7.8.8, a specific CSS-preview request handler in the Cornerstone page builder plugin failed to verify user permissions, inadvertently disclosing sensitive metadata for arbitrary users, including their raw password hashes, to any authenticated user who accessed certain wp-admin pages. This vulnerability specifically affects premium versions of the page builder distributed with X, whereas free versions on the .org repository are not impacted.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings