Description
Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.
Published: 2025-01-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Copy Move Posts plugin for WordPress suffers from a missing authorization flaw (CWE-862) that allows users to copy and move posts without proper privilege checks. The likely attack vector is any authenticated user on the site, as the plugin does not enforce role-based restrictions on these actions. Based on the description, an attacker could duplicate or relocate content, which may enable the insertion of spam, sensitive material, or other malicious content. This represents a moderate security risk with potential for content integrity violations.

Affected Systems

The vulnerability applies to the WordPress plugin "Copy Move Posts" developed by ujjavaljani. Versions from the initial release through and including version 1.6 are affected. WordPress sites that have installed this plugin and have not applied the update to a later release are within scope.

Risk and Exploitability

The CVSS v3.1 score of 5.3 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog, further implying that there are currently no documented public exploits. However, attackers who can authenticate to the site could exploit the broken access control to duplicate or move posts, potentially impacting content integrity and reputation. The risk remains elevated for organizations that rely heavily on post management through this plugin and do not enforce strict role assignments.

Generated by OpenCVE AI on May 2, 2026 at 05:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Copy Move Posts plugin to the latest available version (1.7 or later) that contains the authorization fix.
  • If an upgrade is not immediately possible, restrict the copy/move functionality to users with the Administrator role using role‑based access control settings.
  • If the plugin is no longer required, uninstall it from the WordPress installation.

Generated by OpenCVE AI on May 2, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3398 Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Copy Move Posts: from n/a through 1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Copy Move Posts: from n/a through 1.6. Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Thu, 16 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Copy Move Posts: from n/a through 1.6.
Title WordPress Copy Move Posts plugin <= 1.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:59:03.300Z

Reserved: 2025-01-16T11:29:57.540Z

Link: CVE-2025-23764

cve-icon Vulnrichment

Updated: 2025-01-16T20:38:26.331Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:18.550

Modified: 2026-06-17T08:57:01.140

Link: CVE-2025-23764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:00:13Z

Weaknesses