What the vulnerability does
01Description
Missing Authorization vulnerability in Nate Reist Protected Posts Logout Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protected Posts Logout Button: from n/a through 1.4.5.
Explanation of Vulnerability in Simple Terms
02Summary
The Protected Posts Logout Button plugin for WordPress contains a missing authorization check that allows unauthenticated attackers to modify site content and availability. An attacker can send network requests without authentication to exploit this flaw. Site administrators should update to a version newer than 1.4.5 to prevent unauthorized changes to posts and potential service disruption.
What an attacker can do
03Attacker Capabilities
Modify or disable posts and site functionality without logging in.
Potential impact on your site
04Site Impact
Unauthorized users can alter published posts and affect site availability without your knowledge.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 28, 2026
Record updated