CVE-2026-93507 PUBLISHED

WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure

Assigner: WPScan
Reserved: 18.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

Product Status

Vendor Unknown
Product WC Fields Factory
Versions Default: unaffected
  • affected from 0 to 4.1.11 (excl.)

Credits

  • Farid Narimanov finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE