CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14305

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-07-30
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.

⚡ Watch CVE-2026-14305

Get an email if CVE-2026-14305 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-14305

CVE.org record

Embed the live status

CVE-2026-14305 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14305 status](https://www.csirts.com/badge/CVE-2026-14305)](https://www.csirts.com/cve/CVE-2026-14305)