CVE-2026-93507
WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
| Vendor | unknown |
| Product | wc fields factory |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wc fields factory
Be the first to know when new unknown vulnerabilities affecting unknown wc fields factory are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WC Fields Factory
0 < 4.1.11
References
Credits
Farid Narimanov WPScan