Impact
The WC Fields Factory WordPress plugin before version 4.1.11 fails to enforce proper access checks or validate a nonce when a post‑cloning action is requested, allowing authenticated users with Contributor or higher roles to duplicate any post of any type or status. The resulting cloned post becomes readable to the attacker, exposing private, draft, or otherwise restricted content. The weakness is an authorization control flaw that undermines the intended access restrictions for non‑admin users.
Affected Systems
This vulnerability affects sites using the WC Fields Factory plugin for WordPress, specifically any installation running a version earlier than 4.1.11. The plugin is distributed under the name WC Fields Factory and is listed as an unknown vendor in the CNA records.
Risk and Exploitability
The CVSS score of 3.3 indicates a low severity scenario, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV, implying it has not been observed in widespread attacks. The likely attack vector is an authenticated request to the cloning endpoint, where the lack of nonce validation and insufficient role checks allow the malicious actor to clone arbitrary posts.
OpenCVE Enrichment