The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.
We have discovered 17,691 live websites that are affected by CVE-2026-9709.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 17,691 live websites (79% of THEMECO Cornerstone install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 176 versions ( 82% of all versions) |
| 8,053 websites | |
| 1,878 websites | |
| 1,193 websites | |
| 958 websites | |
| 775 websites | |
| 525 websites | |
| 524 websites | |
| 347 websites | |
| 341 websites | |
| 318 websites |
| .com | 8,705 websites |
| .de | 1,251 websites |
| .org | 1,135 websites |
| .nl | 845 websites |
| .co.uk | 774 websites |
| .com.au | 451 websites |
| .ca | 419 websites |
| .net | 337 websites |
| .se | 298 websites |
| .ch | 293 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.********.com | *** | ||
| ****.com | **,*** | ||
| ********.com | **,*** | ||
| *************.org | **,*** | ||
| ***********.com | **,*** | ||
| ******.com | **,*** | ||
| *******.*****.com | **,*** | ||
| *******************.hr | **,*** | ||
| *******.com | **,*** | ||
| **********.com | **,*** |
FAQ