
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19077 is an Insecure Direct Object Reference (IDOR) / Missing Object-Level Authorization vulnerability in the "Copy & Delete Posts" (Duplicate Post) WordPress plugin before version 1.5.5. The flaw allows any authenticated user who has been granted plugin access by an administrator to permanently delete arbitrary posts site-wide, including posts belonging to other users, via the plugin's bulk copy and delete operations. It was publicly disclosed on August 7, 2026, with a patch released on August 10, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (WPScan, GitHub Advisory).
The root cause is a missing per-object authorization check (CWE-639: Authorization Bypass Through User-Controlled Key) in the plugin's bulk copy and delete operations. When a user submits a bulk delete or copy request, the plugin does not verify whether the requesting user has ownership or sufficient privileges over each individual post object — it only checks whether the user has been granted general access to the plugin by an administrator. An attacker with plugin access can manipulate the post ID key in the request to target arbitrary posts belonging to other users. The vulnerability is classified as OWASP Top 10 A5: Broken Access Control and was discovered and reported by researcher Shikhali Jamalzade (WPScan). A proof-of-concept was scheduled for public release on August 21, 2026, to allow time for users to update (WPScan).
Successful exploitation allows any plugin-enabled user to permanently delete arbitrary posts across the entire WordPress site, regardless of post ownership. This results in high integrity and availability impact — content destruction is irreversible without backups — while there is no confidentiality impact (no data disclosure). The attack can be used for targeted sabotage of other users' content or wholesale destruction of site content, potentially causing significant operational and reputational damage to affected WordPress sites (GitHub Advisory, WPScan).
No public proof-of-concept exploit was available at the time of disclosure (August 10, 2026), with WPScan indicating PoC release was intentionally delayed until August 21, 2026 (WPScan). There is no evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.13–0.23%, placing it in a low exploitation probability tier (GitHub Advisory, Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that an administrator has already granted the attacker's account access to the Duplicate Post plugin, limiting the attack surface.
/wp-content/plugins/copy-delete-posts/readme.txt./wp-json/wp/v2/posts) to enumerate post IDs belonging to other users.wp-admin/admin.php or wp-admin/admin-post.php) with post IDs not owned by the requesting user; repeated bulk delete actions from a single user account in a short timeframe.Update the "Copy & Delete Posts" (Duplicate Post) WordPress plugin to version 1.5.5 or later, which introduces proper per-object authorization checks in bulk operations (WPScan, GitHub Advisory). As an interim workaround, administrators should revoke plugin access from any untrusted or non-essential user roles until the update is applied. After patching, administrators should audit post deletion logs to identify any unauthorized deletions that may have occurred prior to the fix.
The vulnerability was discovered and responsibly disclosed by security researcher Shikhali Jamalzade (Twitter: @0xAlisAlive), who also submitted it to WPScan. WPScan verified the vulnerability and applied a coordinated disclosure timeline, intentionally withholding the proof-of-concept until August 21, 2026, to allow site administrators time to update (WPScan). No broader media coverage or notable community controversy has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."