Vulnerabilities / Parse.ly / WPSEC-2026-0572

Parse.ly <= 3.24.1 - Authenticated (Author+) Sensitive Information Exposure of Private and Draft Posts via REST API

Medium 4.3 CWE-200Fixed in 3.24.2
ID
WPSEC-2026-0572
Plugin
Parse.ly (wp-parsely)
Affected
from 3.17.0 before 3.24.2
Remediation
Update to 3.24.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Parse.ly on WPSec AttackSurface
Fix released
Published

Description

The Parse.ly plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.17.0 up to, and including, 3.24.1 via the post stats REST API routes (/wp-parsely/v2/stats/post/{post_id}/details, /referrers and /related). These routes only check the endpoint-wide capability, not whether the user can access the requested post, and return the request parameters in their response, including the full post object for the requested ID. This makes it possible for authenticated attackers, with Author-level access and above, to read the title, content, status and password of any post, including private, draft and password-protected posts of other users, on sites where a Parse.ly Site ID and API Secret are configured. Smart Linking lookups could also reveal the titles and authors of non-public posts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0