Arbitrary Post Manipulation in IMPress for IDX Broker Plugin by WordPress
CVE-2020-9514
6.5MEDIUM
What is CVE-2020-9514?
A security issue in the IMPress for IDX Broker plugin prior to version 2.6.2 allows logged-in users with Subscriber roles to execute unauthorized actions. This includes the ability to permanently delete existing posts and pages, create new posts with arbitrary titles, and alter the titles of existing posts and pages. Such vulnerabilities can lead to potential misuse of website content and disruption of services.