Authorization Flaw in Sync Post With Other Site Plugin for WordPress
CVE-2026-14923
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 July 2026
Badges
What is CVE-2026-14923?
The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 contains a serious flaw in its authorization mechanism on a REST route that manages post creation and updates. Due to an operator-precedence error, it fails to enforce proper page-editing capabilities, allowing authenticated users with limited permissions, such as Contributors, to create, publish, and modify content on pages. This could lead to unauthorized users overwriting posts, including those authored by users with higher privileges, thereby compromising content integrity and security within the WordPress environment.
Affected Version(s)
Sync Post With Other Site 0 < 1.9.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved