Sync Post With Other Site

Sync Post With Other Site has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Unrestricted Upload Of File With Dangerous Type.

3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

4 independent researchers contributed these findings, one record each. Sync Post With Other Site is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage75%
Open

1

Fixed

3

Get automatic notifications for all Sync Post With Other Site vulnerabilities before they are exploited.

Most severe open issueCVSS 8.8CVE-2026-32463

Sync Post With Other Site <= 1.9.3 - Authenticated (Contributor+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

4 records
Sync Post With Other Site banner
Latestv1.9.3

Sync Post With Other Site

Kamlesh Parmar

Author

Kamlesh Parmar

4.0(28)
80/100
Last Updated
2026-07-06 (2mo ago)
Active Installs
3,000+
Downloads
50,375
Requires WP
4.5+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2020-03-02 (7y ago)

Allows user to sync Posts, Pages and Custom Post Type with multiple websites. If you run multiple websites and want to synchronise them automatically and securely for specific post operations, then Sync Post With Other Site is the plugin to use. You just need to enter website URL & login credentials of other website to sync the post from there. OVERVIEW This plugin adds the following major features to WordPress: admin page: a “Sync Post” menu to manage remote sites. Import and Export: Connected sites’ present posts base can be synchronised manually thanks to the provided import/export tool. Developers Development takes place on GitHub. Patches welcome.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C