Vulnerability Description
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/copy-delete-posts/
- https://www.vulncheck.com/advisories/copy-delete-posts-through-privilege-escalat
FAQ
What is CVE-2026-53738?
CVE-2026-53738 is a vulnerability with a CVSS score of 8.1 (HIGH). Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite pl...
How severe is CVE-2026-53738?
CVE-2026-53738 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53738?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.