Description
WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently schedule deletion of arbitrary posts. WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts version 2.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:DE51B970-AB13-41A6-A479-A92CD0E70B71
https://plugins.svn.wordpress.org/post-expirator/trunk/readme.txt
Related Vulnerabilities
Django Incorrect Regular Expression Vulnerability (CVE-2018-7537)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2019-5482)
WordPress 4.3.x Prototype Pollution (4.3 - 4.3.27)
WordPress Other Vulnerability (CVE-2006-6016)
Internet Information Services CVE-2006-6578 Vulnerability (CVE-2006-6578)