Description
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
Published: 2026-09-23
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Read‑Only Access to Private Content via Arbitrary Post Cloning
Action: Apply Patch
AI Analysis

Impact

The WC Fields Factory WordPress plugin before version 4.1.11 fails to enforce proper access checks or validate a nonce when a post‑cloning action is requested, allowing authenticated users with Contributor or higher roles to duplicate any post of any type or status. The resulting cloned post becomes readable to the attacker, exposing private, draft, or otherwise restricted content. The weakness is an authorization control flaw that undermines the intended access restrictions for non‑admin users.

Affected Systems

This vulnerability affects sites using the WC Fields Factory plugin for WordPress, specifically any installation running a version earlier than 4.1.11. The plugin is distributed under the name WC Fields Factory and is listed as an unknown vendor in the CNA records.

Risk and Exploitability

The CVSS score of 3.3 indicates a low severity scenario, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV, implying it has not been observed in widespread attacks. The likely attack vector is an authenticated request to the cloning endpoint, where the lack of nonce validation and insufficient role checks allow the malicious actor to clone arbitrary posts.

Generated by OpenCVE AI on September 23, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WC Fields Factory plugin to version 4.1.11 or later to receive the authorization fix.
  • If an upgrade cannot be applied immediately, disable the post‑cloning feature for Contributor and lower roles, or restrict it to administrators only.
  • Review and tighten role‑based access controls to ensure that Contributors cannot read or replicate private or draft posts and verify that all related actions enforce proper nonce validation.

Generated by OpenCVE AI on September 23, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
Title WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:51:29.814Z

Reserved: 2026-09-18T08:38:04.455Z

Link: CVE-2026-93507

cve-icon Vulnrichment

Updated: 2026-09-23T10:32:52.856Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:05.843

Modified: 2026-09-23T11:17:17.800

Link: CVE-2026-93507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses