← العودة للجدول
CVE-2026-53738
CVE-2026-53738 — GHSA: Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation...
📅 2026-06-11
🟠 High 🔥 No GHSA Exploit Vulnerability CVSS 8.1

📋 الوصف الكامل

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-53738

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←