Impact
The vulnerability in the Copy & Delete Posts plugin allows a non‑administrator user to invoke any operation in the cdp_action_handling Ajax handler. By passing an f parameter, the attacker can delete posts or overwrite plugin settings, bypassing the normal capability checks that should restrict these actions. This results in unauthorized data deletion and configuration tampering, effectively granting the attacker privileges that should be limited to administrators.
Affected Systems
WordPress sites running Copy & Delete Posts version 1.5.4 or earlier, with the plugin enabled for non‑admin roles. The flaw affects any site that has the plugin installed and configured to be usable by users other than administrators.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity of exposure. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the direct web‑based attack path through the Ajax handler and the lack of prerequisite exploitation steps suggest that the risk of real‑world compromise is significant, especially on sites with many active non‑admin users.
OpenCVE Enrichment