Description
The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it possible for authenticated attackers, with author level access and above, to change the status of arbitrary posts and pages via the REST API endpoint.
Published: 2025-11-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Modification of Post/Page Status via the REST API
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Schedule Post Changes With PublishPress Future plugin allows authenticated authors and higher to modify post and page statuses through the REST API without proper authorization checks. This flaw enables attackers to unpublish, delete, change status, trash, or alter categories of arbitrary content, compromising data integrity.

Affected Systems

Affected systems are WordPress installations running PublishPress Future plugin version 4.9.1 or earlier. The issue applies to all WordPress sites that have the plugin installed and where users with author-level access can use the REST API. No version beyond 4.9.1 is listed as affected.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and an EPSS score of less than 1% points to a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the authenticated REST API endpoint, requiring only author-level credentials, a common privilege in many WordPress sites. Because of these conditions, the overall risk remains low, but any exposed REST API can be a target if an attacker gains author access.

Generated by OpenCVE AI on April 21, 2026 at 18:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PublishPress Future plugin to version 4.9.2 or later, which addresses the authorization check issue.
  • Restrict or disable the affected REST API endpoint for users with author-level access, using a security plugin or .htaccess rules.
  • Audit and tighten WordPress user roles to ensure that only trusted users have author or higher capabilities, and review the plugin’s configuration for any remaining unrestricted actions.

Generated by OpenCVE AI on April 21, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it possible for authenticated attackers, with author level access and above, to change the status of arbitrary posts and pages via the REST API endpoint.
Title Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.1 - Authenticated (Author+) Missing Authorization to Post/Page Status Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:04:04.163Z

Reserved: 2025-11-13T20:11:15.470Z

Link: CVE-2025-13149

cve-icon Vulnrichment

Updated: 2025-11-21T14:53:40.416Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T09:15:46.710

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-13149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T18:15:36Z

Weaknesses