CVE-2026-9709
Last modified
CVE-2026-9709 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.
Metrics
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-9709?
How severe is CVE-2026-9709?
How do I fix CVE-2026-9709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in…7.2
- CVE-2026-97061Black Candy through 3.2.1 fails to scope playlist search que…4.3
- CVE-2026-97062Aureus ERP through 1.6.0 stores uploaded SVG files on its pu…5.4
- CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in…9.1
- CVE-2026-97064X-SpringBoot through 6.0 ships with a hardcoded static maste…9.1
- CVE-2026-9708Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…4.9
- CVE-2026-9710The Cornerstone WordPress plugin before 7.8.8 does not enfor…7.7
- CVE-2026-9711The EventON - WordPress Virtual Event Calendar Plugin plugin…9.8
- CVE-2026-9712When creating an export through the pretix API, API clients …3.8
- CVE-2026-9713The Lumise Product Designer for WooCommerce plugin for WordP…7.5
- CVE-2026-9714The Simple Divi Shortcode plugin for WordPress is vulnerable…6.4
- CVE-2026-97149In OpenStack Swift before 2.38.2, the tempurl middleware doe…5.3
Are you affected by CVE-2026-9709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
