Vulnerability found – please update!
-
https://research.cleantalk.org/reports/app/copy-delete-posts#249337
Duplicate Post # CVE-2026-53738 CVE, Research URLCVE-2026-53738Home page URL
Security reports for Duplicate PostApplication
Duplicate PostDateJun 11, 2026Research DescriptionCopy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.Affected versions
max 1.5.4.
Status: vulnerable
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
You must be logged in to reply to this topic.