Post Expirator <= 2.5.1 - Contributor+ Arbitrary Post Schedule Deletion
2021-10-11 00:00
apple502jStrategic Overview
StatusPatched in 2.6.0
Affected PluginSchedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
Affected Version
<= 2.5.1CVSS4.3Medium
CVE
CVE-2021-24783Vulnerability Overview
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
Technical Analysis
REMEDIATION: Update to version 2.6.0, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C