Access violation vulnerability in Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories 4.9.1

The plugin “Schedule Post Changes With PublishPress Future” for WordPress has a security vulnerability that allows unauthorized changes to be made to data. This is because the “saveFutureActionData” function does not have proper authorization checks in place. This means that attackers with author level access or higher can use the REST API endpoint to change the status of any posts or pages.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.