What the vulnerability does
01Description
Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.
Explanation of Vulnerability in Simple Terms
The Delete Duplicate Posts plugin for WordPress does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify or delete posts they should not have access to. The vulnerability affects versions up to 4.8.9. Site administrators should update the plugin to a version newer than 4.8.9.
What an attacker can do
A low-privilege user can modify or delete posts without proper authorization checks.
Potential impact on your site
Unauthorized users may delete or alter post content, compromising site integrity and editorial control.
Conditions required to exploit
Attacker must have a WordPress user account with low-level privileges (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities