What the vulnerability does
01Description
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
Explanation of Vulnerability in Simple Terms
02Summary
Newspack Content Converter versions up to 0.1.5 lack proper authorization checks, allowing authenticated users with low privileges to modify content they should not have access to. An attacker with a basic user account can change or delete posts and pages belonging to other users or protected content areas. This vulnerability affects any WordPress site using the plugin where user roles and permissions are relied upon to restrict editing capabilities.
What an attacker can do
03Attacker Capabilities
Modify or delete posts and pages belonging to other users or restricted content areas.
Potential impact on your site
04Site Impact
Content integrity is at risk; unauthorized users can alter or remove published posts, pages, and other content.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., Contributor or Author) on the WordPress site.
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated