WordPress Plugin Vulnerabilities

Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification

Description

The plugin does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.

Proof of Concept

Affects Plugins

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-09 (about 2 months ago)
Added
2026-07-09 (about 2 months ago)
Last Updated
2026-07-09 (about 2 months ago)

Other