๐Ÿ” CVE Alert

CVE-2026-14923

MEDIUM 6.5

Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification

CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
5th

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.

Vendor unknown
Product sync post with other site
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sync post with other site

Be the first to know when new medium vulnerabilities affecting unknown sync post with other site are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Sync Post With Other Site
0 < 1.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/cc635e60-f80e-4399-a016-9fde9228c58c/

Credits

Shikhali Jamalzade WPScan