Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Project Subscriptions

Vendors Products
Copy-delete-posts Subscribe
Duplicate Post Subscribe
Copy & Delete Posts Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Inisev
Inisev copy & Delete Posts
Wordpress
Wordpress wordpress
Vendors & Products Inisev
Inisev copy & Delete Posts
Wordpress
Wordpress wordpress

Wed, 10 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.
Title Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler
First Time appeared Copy-delete-posts
Copy-delete-posts duplicate Post
Weaknesses CWE-863
CPEs cpe:2.3:a:copy-delete-posts:duplicate_post:*:*:*:*:*:wordpress:*:*
Vendors & Products Copy-delete-posts
Copy-delete-posts duplicate Post
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-10T20:39:43.269Z

Reserved: 2026-06-10T17:16:10.427Z

Link: CVE-2026-53738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-10T22:17:02.093

Modified: 2026-06-10T22:17:02.093

Link: CVE-2026-53738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T10:40:48Z

Weaknesses