Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler
CVE-2026-53738

7.2HIGH

Key Information:

Vendor

Inisev

Vendor
CVE Published:
10 June 2026

What is CVE-2026-53738?

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Affected Version(s)

Copy & Delete Posts 0 <= 1.5.4

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scott Moore - VulnCheck
.