Insecure Direct Object Reference in Post Type Switcher Plugin for WordPress
CVE-2025-12524
5.4MEDIUM
What is CVE-2025-12524?
The Post Type Switcher plugin for WordPress is susceptible to Insecure Direct Object Reference due to inadequate validation on user-controlled keys. Authenticated attackers with Author-level access or higher can exploit this vulnerability to alter the post type of arbitrary posts and pages, including those owned by administrators. Such unauthorized modifications could lead to significant site disruptions, hindered navigation, and negative impacts on search engine optimization. Proper risk management and timely updates to the plugin are critical to safeguarding your WordPress site.
Affected Version(s)
Post Type Switcher * <= 4.0.0