SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14923

MEDIUM · CVSS 6.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 has a vulnerability that allows authenticated users with limited post-editing capabilities to create, publish, and overwrite arbitrary pages due to an authorization flaw. This could lead to unauthorized content modification, potentially impacting the integrity of site content authored by users with higher privileges. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14923
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%
WordPress

Original NVD Description

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.