Post Type Switcher
Post Type Switcher has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).
The one issue recorded for Post Type Switcher has a vendor fix available, so running the current release closes it.
All of these findings were reported by Athiwat Tiprasaharn (Jitlada). Post Type Switcher is installed on roughly 200,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-12524Post Type Switcher <= 4.0.0 - Insecure Direct Object Reference to Authenticated (Author+) Post Type Change
Read the full analysisVulnerability Records

Post Type Switcher
Author
John James Jacoby
This plugin adds a simple post-type drop-down to the post editor interface, allowing you to reassign any post to a new post type. It allows you to switch post’s type while editing your post. Supported Types The plugin can convert nearly every combination of posts, pages, and even custom post types: Page to Post Post to Page Post to Custom Custom to Custom As of 3.0.0, support for switching to or from Attachments was removed. This may come back in a subsequent version. Invisible post types, such as revisions, menus, etc., are purposely excluded. But, if you need to access invisible post types, you can adjust the boundaries using the ‘pts_post_type_filter’ filter. Bulk Editing With bulk editing (thanks to Matthew Gerring) you can select all the posts in a certain type and convert them to a new type with one quick action. Block Editor With block-editor (aka Gutenberg) support (thanks to Daniel Bachhuber) you can switch between post-types that use either the Block Editor and the Classic one, without losing any of your embedded content.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C