The WC Fields Factory WordPress plugin before 4.1.11 does...
Low severity
Unreviewed
Published
Sep 23, 2026
to the GitHub Advisory Database
•
Updated Sep 23, 2026
Description
Published by the National Vulnerability Database
Sep 23, 2026
Published to the GitHub Advisory Database
Sep 23, 2026
Last updated
Sep 23, 2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
References