Missing Authorization Vulnerability in Company Posts for LinkedIn Plugin by WordPress
CVE-2026-1935
4.3MEDIUM
What is CVE-2026-1935?
The Company Posts for LinkedIn plugin for WordPress has a vulnerability due to a lack of necessary capability checks in its functionality. Specifically, the function linkedin_company_post_reset_handler() does not properly validate user permissions before executing, which enables authenticated attackers with Subscriber-level access or higher to delete LinkedIn post information stored in the site's options table. This flaw poses a significant risk to the integrity of user data and highlights the need for secure coding practices in WordPress plugins.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Company Posts for LinkedIn * <= 1.0.0