WordPress Plugin Vulnerabilities

WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure

Description

The plugin does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

Proof of Concept

Affects Plugins

Fixed in 4.1.11

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other