WordPress Plugin Vulnerabilities

Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization

Description

The plugin does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted plugin access to permanently delete arbitrary posts on the site, including those belonging to other users.

Proof of Concept

Affects Plugins

Fixed in 1.5.5

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-07 (about 3 days ago)
Added
2026-08-07 (about 2 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other