CVE-2026-4431 (matched: wordpress)

  • Wednesday, 5th August, 2026
  • 10:05am

A security vulnerability has been identified in the Easy Post Submission plugin for WordPress, a tool many site owners use to let visitors submit content to their websites. The flaw impacts all versions of the plugin up to and including version 2.3.0.

The issue is caused by a missing permission check on a core plugin feature that was supposed to restrict access to authorized users only. This gap allows people who do not have a login for your WordPress site to access and use this feature to make changes to existing posts on your site.

These unauthenticated users could edit a post's title, main content, summary, tags, and categories, or even unpublish posts entirely by switching their status to draft. No special access or login credentials are needed to carry out these changes.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4431

« Back