The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy. | |
| Title | WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:51:29.814Z
Reserved: 2026-09-18T08:38:04.455Z
Link: CVE-2026-93507
Updated: 2026-09-23T10:32:52.856Z
Status : Received
Published: 2026-09-23T06:17:05.843
Modified: 2026-09-23T11:17:17.800
Link: CVE-2026-93507
No data.
OpenCVE Enrichment
No data.
Weaknesses