Missing Authorization in Ujjaval Jani Copy Move Posts Plugin
CVE-2025-23764
5.3MEDIUM
Summary
The Copy Move Posts plugin by Ujjaval Jani is vulnerable due to improper access control settings, which can result in unauthorized actions. This vulnerability may allow attackers to exploit misconfigured security levels and gain inconsistent access to post manipulation features. It is essential for users to ensure proper security measures and limit access to sensitive functionalities in their WordPress environment.
Affected Version(s)
Copy Move Posts <= 1.6
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)