automattic/zoninator is vulnerable to Incorrect Authorization
79
High Risk
The wp_ajax_zoninator_search_posts handler was previously reachable by any authenticated user and returned information about scheduled (future) posts, enabling an authorization-bypass style information disclosure. Additionally, the REST GET /wp-json/zoninator/v1/zones endpoint now requires a logged-in user by default via get_zones_permissions_check, preventing anonymous access unless restored by an explicit filter.
You are affected if you are using a version that falls within the vulnerable range.
automattic/zoninator is vulnerable to Incorrect Authorization in versions 0.0.1 - 0.10.2.
Upgrade the automattic/zoninator library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant