Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

WordPress Plugin reveals sensitive user information

CVE-2026-0025 ASB-A-433746973
Summary

A security issue in WordPress allows an attacker to access information about other users without permission, potentially leading to unauthorized access to sensitive data. Affected users should update their WordPress installation to the latest version to prevent this issue. This vulnerability can be exploited without user interaction, making it a priority to patch as soon as possible.

What to do
  • Update google platform/frameworks/base to version 16-qpr2-next:2026-03-01.
  • Update google platform/frameworks/base to version 15:2026-03-01.
  • Update google platform/frameworks/base to version 16:2026-03-01.
  • Update google platform/frameworks/base to version 16-qpr2:2026-03-01.
  • Update google platform/frameworks/base to version 14:2026-03-01.
Affected software
VendorProductAffected versionsFix available
google android 14.0
google android 15.0
google android 16.0
google android 16.0
google android 16.0
google android 16.0
google platform/frameworks/base > 16-qpr2-next:0 , <= 16-qpr2-next:2026-03-01 16-qpr2-next:2026-03-01
google platform/frameworks/base > 15:0 , <= 15:2026-03-01 15:2026-03-01
google platform/frameworks/base > 16:0 , <= 16:2026-03-01 16:2026-03-01
google platform/frameworks/base > 16-qpr2:0 , <= 16-qpr2:2026-03-01 16-qpr2:2026-03-01
google platform/frameworks/base > 14:0 , <= 14:2026-03-01 14:2026-03-01
Original title
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional executi...
Original description
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd CVSS3.1 8.4
Vulnerability type
CWE-200 Information Exposure
Published: 1 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026