Impact
The Smart Post WordPress plugin (versions 4.0.0 through 4.0.7) allows users with contributor privileges or higher to request a post duplicate without verifying the type, ownership, or status of the target post. This omission lets those users create a draft copy of any private or password‑protected post, thereby exposing its content and metadata. The weakness is a typical example of improper access control in which privileged users can read data they should not be able to access.
Affected Systems
WordPress sites that have installed Smart Post version 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6 or 4.0.7 and enable the duplicate‑post feature. Users of the Contributor role or higher are susceptible to the disclosure vulnerability.
Risk and Exploitability
The plugin’s CVSS score is not listed, and EPSS data is unavailable, so the likelihood of exploitation in the wild cannot be quantified. No CISA KEV entry exists for this vulnerability. An attacker requiring no special network privileges has access to the application’s duplicate‑post endpoint and can directly copy a private or password‑protected post to a draft, revealing its content. The vulnerability is exploitable on any site that permits contributor activity and has the affected plugin version. The impact is solely data confidentiality breach for posts marked private or password‑protected.
OpenCVE Enrichment