Post Expirator <= 2.5.1 - Contributor+ Arbitrary Post Schedule Deletion

2021-10-11 00:00
apple502j

Vulnerability Overview

The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.

Technical Analysis

REMEDIATION: Update to version 2.6.0, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C