PT-2026-48552 · WordPress · Copy & Delete Posts

CVE-2026-53738

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Copy & Delete Posts versions prior to 1.5.5
Description Any non-admin role with plugin enabled permissions can invoke all operations within the cdp action handling AJAX handler. By manipulating the f parameter, an attacker can bypass per-function capability checks to delete posts or overwrite plugin settings.
Recommendations Update to version 1.5.5 or later.

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53738

Affected Products

Copy & Delete Posts