low · CVSS v3 3.3 · EPSS 0.0018
CVE-2026-93507
The WC Fields Factory WordPress plugin (v4.1.10 and earlier) fails to enforce proper access checks or nonce verification for post-cloning ac
Overview
The WC Fields Factory WordPress plugin (v4.1.10 and earlier) fails to enforce proper access checks or nonce verification for post-cloning actions. This flaw allows users with Contributor or higher roles to duplicate any post, including private or draft content, and read the resulting copy. The vulnerability exposes sensitive content to unauthorized contributors.
Description
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
Impact
Confidentiality is compromised as private or draft posts can be duplicated and read by contributors. The integrity of content ownership is weakened because the original author’s control over their posts is bypassed. Site administrators and content owners are directly impacted.
Remediation
1. Upgrade the WC Fields Factory plugin to version 4.1.11 or later, where the access check and nonce validation are fixed. 2. If an upgrade is not immediately possible, temporarily revoke Contributor role permissions for post cloning or disable the cloning feature via plugin settings or custom code. 3. Verify that role capabilities are correctly configured and monitor audit logs for unexpected post duplication activity.
Risk context
Severity is low (CVSS 3.3) and EPSS is 0.0018, indicating a very low probability of exploitation. However, the impact on confidentiality for private or draft content warrants timely remediation.
Affected products
- WC Fields Factory WordPress plugin
Scores
- Severity
- low
- CVSS v2
- 3.2
- CVSS v3
- 3.3
- CVSS v4
- —
- EPSS
- 0.0018