CVE-2026-4431 (matched: wordpress)

  • Wednesday, 5th August, 2026
  • 16:04pm

A security flaw has been identified in the Easy Post Submission plugin for WordPress, a tool often used to allow visitors to submit content to your site. This issue affects all versions of the plugin up to and including version 2.3.0. Normally, only authorized, logged-in users (such as your site administrators) should be able to edit existing posts on your WordPress site. But this bug creates a gap that lets anyone, even people who are not logged into your site at all, make changes to your posts by sending a specific type of request to your website. Attackers could exploit this gap to edit the titles, main content, summaries, categories, and tags of any of your published posts. They could also unpublish posts entirely by changing their status to draft, without needing any login credentials to carry out these changes.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4431

« Back