PT-2026-8047 · WordPress · Wp Last Modified Info

·

CVE-2025-14608

·

Published

2026-02-14

·

Updated

2026-02-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Last Modified Info plugin for WordPress versions up to and including 1.9.5
Description The WP Last Modified Info plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. The plugin does not properly validate a user’s access rights to a post before altering its metadata within the 'bulk save' AJAX action. This allows authenticated attackers with Author-level access or higher to modify the last modified metadata and lock the modification date of any post, even those created by Administrators. The manipulation is performed through the post ids parameter.
Recommendations Update the WP Last Modified Info plugin to a version later than 1.9.5.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14608

Affected Products

Wp Last Modified Info