CVE-2026-9709

Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Meta Disclosure

The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.


We have discovered 17,691 live websites that are affected by CVE-2026-9709.

Run a Free Instant Scan




Affected Software

Product  THEMECO Cornerstone
Category Wordpress Plugins
Vulnerable Domains17,691 live websites (79% of THEMECO Cornerstone install base)
Vulnerable Versions
  • from 3 through 7.8.9
Vulnerable Versions Count176 versions ( 82% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jun 24, 2026
  • Updated - Jun 24, 2026

Credits

  • Real_King_Engine (ISAL FRAMEWORK) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-9709
United States8,053 websites



Germany1,878 websites
GB1,193 websites
Netherlands958 websites
Canada775 websites
France525 websites
Australia524 websites
Denmark347 websites
Italy341 websites
Switzerland318 websites

Website Distribution by TLD

Number of websites using CVE-2026-9709
.com8,705 websites
.de1,251 websites
.org1,135 websites
.nl845 websites
.co.uk774 websites
.com.au451 websites
.ca419 websites
.net337 websites
.se298 websites
.ch293 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-9709

Top websites that are affected by CVE-2026-9709. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***
****.com United States**,***
********.com United States**,***
*************.org United States**,***
***********.com United States**,***
******.com United States**,***
*******.*****.com Korea, South**,***
*******************.hr Croatia**,***
*******.com United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2026-9709 is Exposure of Sensitive Information to an Unauthorized Actor in THEMECO Cornerstone
A total of 17,691 websites have been identified as vulnerable to CVE-2026-9709, based on global website indexing conducted by WebTechSurvey.
The THEMECO Cornerstone is affected by the CVE-2026-9709 vulnerability.
THEMECO Cornerstone versions up to 7.8.9 are vulnerable to CVE-2026-9709.
CVE-2026-9709 is resolved in version 7.8.9 of THEMECO Cornerstone.