Delete Duplicate Posts <= 4.8.9 - Missing Authorization via AJAX Actions

2023-11-13 00:00
Huynh Tien Si

Strategic Overview

Status
Patched in 4.9
Affected PluginDelete Duplicate Posts
Affected Version< 4.9
CVSS5.4Medium
CVECVE-2023-47754
View all Delete Duplicate Posts vulnerabilities

Vulnerability Overview

The Delete Duplicate Posts plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on some of its AJAX actions in all versions up to 4.9 (exclusive). This makes it possible for authenticated attackers, with subscriber access or higher, to delete duplicate posts, access plugin logs, and opt in to Freemius data gathering.

Technical Analysis

REMEDIATION: Update to version 4.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C