CVE-2026-19699
Description
AI Translation Available
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
https://wpscan.com/vulnerability/301f10fd-ac72-4d80-8ca3-402a4a55ba3d/