Easy Post Submission <= 2.3.0 - Missing Authorization
critical
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv...
- CVSS:
- 9.1
- Affected:
- up to 2.3.0
- Fixed in:
- 2.4.0
- Disclosed:
- Aug 4, 2026
CVE-2026-4431 on NVD →
Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress <= 2.4.0 - Missing Authorization
medium
The Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 5.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.5.0
- Disclosed:
- Mar 4, 2026
CVE-2026-22479 on NVD →
Easy Post Submission <= 1.7.0 - Unauthenticated Sensitive Information Exposure
medium
The Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.7.0
- Fixed in:
- 2.0.0
- Disclosed:
- Oct 16, 2025
CVE-2025-62062 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database