CVE-2026-14923
Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification
CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
5th
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.
| Vendor | unknown |
| Product | sync post with other site |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown sync post with other site
Be the first to know when new medium vulnerabilities affecting unknown sync post with other site are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Sync Post With Other Site
0 < 1.9.3
References
Credits
Shikhali Jamalzade WPScan