Description
WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently schedule deletion of arbitrary posts. WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts version 2.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:DE51B970-AB13-41A6-A479-A92CD0E70B71
https://plugins.svn.wordpress.org/post-expirator/trunk/readme.txt
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0793)
WordPress Plugin WooCommerce Stock Manager Cross-Site Request Forgery (2.5.7)
WebLogic Improper Access Control Vulnerability (CVE-2019-2729)
XWiki Improper Handling of Exceptional Conditions Vulnerability (CVE-2023-29520)