CVE-2026-9709 Details
Description
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.
A vulnerability in the Cornerstone WordPress plugin, specifically in versions prior to 7.8.9, allows authenticated users to access and disclose metadata of other users through a REST API route that lacks proper capability checks. This vulnerability affects the premium Cornerstone page builder bundled with the X Theme, not the free Cornerstone plugin available on the WordPress.org repository. The exposed metadata includes user roles, session token previews, and WooCommerce billing and shipping information.
Users are advised to update the Cornerstone WordPress plugin to version 7.8.9 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/3ade0e4e-2070-4d3b-8f31-0d446839efd0/ | CISA-ADP | AdvisoryExploitRemedy |
| https://wpscan.com/vulnerability/3ade0e4e-2070-4d3b-8f31-0d446839efd0/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Themeco Cornerstone | < 7.8.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion