Lucene search

K
wpvulndbApple502jWPVDB-ID:A7FA5896-5A1D-44C6-985C-E4ABCC53DA0E
HistoryDec 27, 2021 - 12:00 a.m.

WP Post Page Clone < 1.2 - Unauthorised Post Access

2021-12-2700:00:00
apple502j
wpscan.com
8

0.001 Low

EPSS

Percentile

24.8%

The plugin allows users with a role as low as Contributor to clone and view other users’ draft and password-protected posts which they cannot view normally.

PoC

Go to All Posts, find the post to clone, click “Click to Clone” then edit the cloned post to see its content

CPENameOperatorVersion
wp-post-page-clonelt1.2

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:A7FA5896-5A1D-44C6-985C-E4ABCC53DA0E