Loading market data...
← Back to CVE feed

CVE-2026-93507

LOW CVSS 3.3 View on NVD ↗

Description

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Published: Sep 23, 2026 06:17 UTC Modified: Sep 23, 2026 18:12 UTC