# Parse.ly <= 3.24.1 - Authenticated (Author+) Sensitive Information Exposure of Private and Draft Posts via REST API

- **ID:** WPSEC-2026-0572
- **Plugin:** Parse.ly (`wp-parsely`), https://wordpress.org/plugins/wp-parsely/
- **Affected versions:** from 3.17.0 before 3.24.2
- **Fixed in:** 3.24.2 (Update to 3.24.2 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-parsely
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0572/

## Description

The Parse.ly plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.17.0 up to, and including, 3.24.1 via the post stats REST API routes (/wp-parsely/v2/stats/post/{post_id}/details, /referrers and /related). These routes only check the endpoint-wide capability, not whether the user can access the requested post, and return the request parameters in their response, including the full post object for the requested ID. This makes it possible for authenticated attackers, with Author-level access and above, to read the title, content, status and password of any post, including private, draft and password-protected posts of other users, on sites where a Parse.ly Site ID and API Secret are configured. Smart Linking lookups could also reveal the titles and authors of non-public posts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0572/
- https://plugins.svn.wordpress.org/wp-parsely/tags/3.24.2/
- https://wordpress.org/plugins/wp-parsely/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0572/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
