Impact
The vulnerability in the Schedule Post Changes With PublishPress Future plugin allows authenticated authors and higher to modify post and page statuses through the REST API without proper authorization checks. This flaw enables attackers to unpublish, delete, change status, trash, or alter categories of arbitrary content, compromising data integrity.
Affected Systems
Affected systems are WordPress installations running PublishPress Future plugin version 4.9.1 or earlier. The issue applies to all WordPress sites that have the plugin installed and where users with author-level access can use the REST API. No version beyond 4.9.1 is listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and an EPSS score of less than 1% points to a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the authenticated REST API endpoint, requiring only author-level credentials, a common privilege in many WordPress sites. Because of these conditions, the overall risk remains low, but any exposed REST API can be a target if an attacker gains author access.
OpenCVE Enrichment