Insecure Direct Object Reference in Post Type Switcher Plugin for WordPress
CVE-2025-12524

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-12524?

The Post Type Switcher plugin for WordPress is susceptible to Insecure Direct Object Reference due to inadequate validation on user-controlled keys. Authenticated attackers with Author-level access or higher can exploit this vulnerability to alter the post type of arbitrary posts and pages, including those owned by administrators. Such unauthorized modifications could lead to significant site disruptions, hindered navigation, and negative impacts on search engine optimization. Proper risk management and timely updates to the plugin are critical to safeguarding your WordPress site.

Affected Version(s)

Post Type Switcher * <= 4.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-12524 : Insecure Direct Object Reference in Post Type Switcher Plugin for WordPress