Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Project Subscriptions

Vendors Products
Copy-delete-posts Subscribe
Duplicate Post Subscribe
Copy & Delete Posts Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Inisev
Inisev copy & Delete Posts
Wordpress
Wordpress wordpress
Vendors & Products Inisev
Inisev copy & Delete Posts
Wordpress
Wordpress wordpress

Wed, 10 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.
Title Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler
First Time appeared Copy-delete-posts
Copy-delete-posts duplicate Post
Weaknesses CWE-863
CPEs cpe:2.3:a:copy-delete-posts:duplicate_post:*:*:*:*:*:wordpress:*:*
Vendors & Products Copy-delete-posts
Copy-delete-posts duplicate Post
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-11T14:17:29.536Z

Reserved: 2026-06-10T17:16:10.427Z

Link: CVE-2026-53738

cve-icon Vulnrichment

Updated: 2026-06-11T14:17:25.858Z

cve-icon NVD

Status : Deferred

Published: 2026-06-10T22:17:02.093

Modified: 2026-06-11T15:22:26.633

Link: CVE-2026-53738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T10:40:48Z

Weaknesses