Sync Post With Other Site
Sync Post With Other Site has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Unrestricted Upload Of File With Dangerous Type.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
4 independent researchers contributed these findings, one record each. Sync Post With Other Site is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-32463Sync Post With Other Site <= 1.9.3 - Authenticated (Contributor+) Arbitrary File Upload
Read the full analysisVulnerability Records

Sync Post With Other Site
Author
Kamlesh Parmar
Allows user to sync Posts, Pages and Custom Post Type with multiple websites. If you run multiple websites and want to synchronise them automatically and securely for specific post operations, then Sync Post With Other Site is the plugin to use. You just need to enter website URL & login credentials of other website to sync the post from there. OVERVIEW This plugin adds the following major features to WordPress: admin page: a “Sync Post” menu to manage remote sites. Import and Export: Connected sites’ present posts base can be synchronised manually thanks to the provided import/export tool. Developers Development takes place on GitHub. Patches welcome.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C