Vulnerabilities (CVE)

Filtered by vendor Publishpress Subscribe
Filtered by product Post Expirator
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24783 1 Publishpress 1 Post Expirator 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.