🔐 CVE Alert

CVE-2026-4431

CRITICAL 9.1

Easy Post Submission <= 2.3.0 - Missing Authorization

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter.

CWE CWE-862
Vendor themeruby
Product easy post submission – frontend posting, guest publishing & submit content for wordpress
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for themeruby easy post submission – frontend posting, guest publishing & submit content for wordpress

Be the first to know when new critical vulnerabilities affecting themeruby easy post submission – frontend posting, guest publishing & submit content for wordpress are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

themeruby / Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
0 ≤ 2.3.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/15494ccf-7c9d-4566-9e80-2da94172a3dd?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L38 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L974 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L1157 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3488045%40easy-post-submission%2Ftrunk&old=3427523%40easy-post-submission%2Ftrunk

Credits

Md. Moniruzzaman Prodhan (NomanProdhan)