rootpwn

low · CVSS v3 3.3 · EPSS 0.0018

CVE-2026-93507

The WC Fields Factory WordPress plugin (v4.1.10 and earlier) fails to enforce proper access checks or nonce verification for post-cloning ac

Overview

The WC Fields Factory WordPress plugin (v4.1.10 and earlier) fails to enforce proper access checks or nonce verification for post-cloning actions. This flaw allows users with Contributor or higher roles to duplicate any post, including private or draft content, and read the resulting copy. The vulnerability exposes sensitive content to unauthorized contributors.

Description

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

Impact

Confidentiality is compromised as private or draft posts can be duplicated and read by contributors. The integrity of content ownership is weakened because the original author’s control over their posts is bypassed. Site administrators and content owners are directly impacted.

Remediation

1. Upgrade the WC Fields Factory plugin to version 4.1.11 or later, where the access check and nonce validation are fixed. 2. If an upgrade is not immediately possible, temporarily revoke Contributor role permissions for post cloning or disable the cloning feature via plugin settings or custom code. 3. Verify that role capabilities are correctly configured and monitor audit logs for unexpected post duplication activity.

Risk context

Severity is low (CVSS 3.3) and EPSS is 0.0018, indicating a very low probability of exploitation. However, the impact on confidentiality for private or draft content warrants timely remediation.

Affected products

  • WC Fields Factory WordPress plugin

Scores

Severity
low
CVSS v2
3.2
CVSS v3
3.3
CVSS v4
EPSS
0.0018

wordpress plugin post-cloning confidentiality role-based-access low-severity CVE-2026-93507

← All CVEs