CyberRota Analysis
AI-GeneratedThe Sync Post With Other Site plugin for WordPress prior to version 1.9.3 has a vulnerability that allows authenticated users with limited post-editing capabilities to create, publish, and overwrite arbitrary pages due to an authorization flaw. This could lead to unauthorized content modification, potentially impacting the integrity of site content authored by users with higher privileges. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.